Courseiva
Implementing network securityhardMultiple SelectObjective-mapped

PCNE Implementing network security Practice Question

A network engineer is troubleshooting connectivity issues with VPC Flow Logs. Which TWO statements about VPC Flow Logs are correct? (Choose TWO)

⚠ Common exam trap

Google Cloud often tests the misconception that VPC Flow Logs capture every packet or only allowed traffic, when in reality they sample flows and log both accepted and rejected traffic, making options B and D common traps.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

VPC Flow Logs can be used to diagnose overly permissive firewall rules.

VPC Flow Logs capture metadata about accepted and rejected traffic, including traffic that is allowed by overly permissive firewall rules. By analyzing the logs, you can identify flows that should have been blocked, revealing rules that are too broad in scope (e.g., allowing all traffic from 0.0.0.0/0). This diagnostic capability directly helps tighten security posture.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • VPC Flow Logs capture only egress traffic.

    Why it's wrong here

    They capture both ingress and egress traffic.

  • VPC Flow Logs only capture traffic that is allowed by firewall rules.

    Why it's wrong here

    They capture both allowed and denied traffic (if logging is enabled for the rule).

  • VPC Flow Logs can be used to diagnose overly permissive firewall rules.

    Why this is correct

    By analyzing logs, you can see allowed traffic and identify rules that are too broad.

  • VPC Flow Logs capture all packets for every flow in the VPC.

    Why it's wrong here

    Flow logs are sampled (default 1 per 10 packets) and not all flows are captured.

  • VPC Flow Logs do not capture traffic that is generated by GCP health checks.

    Why this is correct

    Health check traffic is excluded from flow logs.

About these practice questions

This PCNE question is part of Courseiva's 961-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNE exam.