Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise organization is designing a zero-trust network perimeter architecture for sensitive backend workloads hosted on Google Cloud Compute Engine instances across multiple VPC networks. The security engineering team has established the following technical requirements:
Which combination of actions should the security team implement?
This solution implements a defense-in-depth, zero-trust network perimeter by combining Cloud Next Generation Firewall (NGFW) threat feeds and Layer 7 deep packet inspection with Identity-Aware Proxy (IAP) context-aware access controls.
iplist-tor-exit-nodes and iplist-known-malicious-ips) can be referenced directly inside hierarchical or global network firewall policies with a deny action. These feeds dynamically update to block malicious traffic without requiring manual IP range maintenance.apply_security_profile_group action and --tls-inspect flag allows firewall endpoints to inspect decrypted session payloads for vulnerabilities, malware, and spyware signatures.35.235.240.0/20, allowing strict ingress firewall rules paired with IAM and context-aware access evaluation.Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.