Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise is architecting a mission-critical, three-tier application (Web, Application, and Database tiers) across dedicated subnets within a Google Cloud Shared VPC. The central security team requires strict boundary segmentation with the following requirements:
Which network security design should the enterprise implement to satisfy these requirements?
Hierarchical firewall policies allow security administrators to define and enforce consistent firewall rules across the entire resource hierarchy (organization, folders, and projects) in Google Cloud. When combined with Resource Manager secure tags and service account identities, access control is bound directly to verified identity and governed metadata rather than mutable network properties or legacy network tags.
tagKeys/env/tagValues/web tag), ensuring strict east-west segmentation.roles/resourcemanager.tagUser). Workload administrators with compute instance edit permissions cannot add or remove secure tags unless explicitly granted tag administration rights, preventing unauthorized privilege escalation or boundary bypass.This solution provides tamper-proof, centrally administered boundary protection that couples identity-aware filtering with hierarchical policy controls, preventing lateral movement without requiring complex routing topologies or external appliances.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.