Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A security engineer is designing an application-layer intrusion detection strategy for a mission-critical financial processing workload running across multiple zones in a single Google Cloud region. The workload experiences a sustained traffic volume of 12 Gbps, requires deep Layer 7 inspection of both ingress/egress and east-west intra-subnet lateral communications for malware and command-and-control activity, and must identify applications regardless of the ports used.
During testing, specific benign internal maintenance tasks triggered false-positive alerts against standard intrusion signatures.
Which configuration should the security engineer deploy to inspect this application traffic and tune the detection profile?
Cloud IDS (Intrusion Detection System) is a cloud-native, Google-managed threat detection service powered by Palo Alto Networks security technologies. It provides deep packet inspection across Layer 7 network traffic, identifying intrusions, malware, spyware, and command-and-control (C2) attacks. It uses App-ID to accurately classify application traffic traversing the network regardless of port, protocol, or evasion tactics.
This architecture directly addresses high-throughput scaling (3 endpoints for 12 Gbps), full east-west packet mirroring visibility, App-ID Layer 7 classification, and precision alert tuning using threat exceptions.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.