Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A security engineer is designing an egress perimeter control architecture for Google Cloud workloads located in a VPC across multiple zones. The organization requires Layer 7 traffic inspection to filter outbound HTTP and HTTPS connections based on domain matcher strings and TLS Server Name Indication (SNI), applying custom block or allow actions.
Which combination of components and configuration steps should the engineer implement to meet these requirements?
Cloud Next Generation Firewall (NGFW) Enterprise URL filtering provides native Layer 7 egress inspection for HTTP and HTTPS traffic without requiring third-party proxy appliances or sidecar agents. It inspects Host headers and TLS Server Name Indication (SNI) fields during session negotiation to enforce granular domain-level access policies.
apply_security_profile_group action to route matching connections to the firewall endpoint for Layer 7 evaluation.This architecture directly leverages Google Cloud's native NGFW Enterprise constructs, fulfilling all Layer 7 domain filtering, SNI matching, and automated enforcement requirements while maintaining high throughput and low latency.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.