Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise has deployed Cloud Next-Generation Firewall (Cloud NGFW) Enterprise with Intrusion Prevention Service (IPS) profiles and TLS inspection to secure sensitive workloads within a VPC network. The Security Operations Center (SOC) is investigating suspicious outbound Layer 7 application traffic suspected of being command-and-control (C2) communication.
The security team must:
Which logging analysis and integration strategy should the security engineer implement?
Query Cloud NAT logging to extract threat signature payloads, and schedule a daily Cloud Storage Transfer Service job to push the logs to the SIEM.
Enable VPC Flow Logs on all subnetworks, filter for TCP connection reset flags in Cloud Monitoring, and use Cloud Functions to trigger hourly webhook alerts to the external SIEM.
Query Cloud NGFW threat logs in Cloud Logging to evaluate threat_id, application_name, and action in the jsonPayload, and configure a filtered Log Router sink streaming to a Pub/Sub topic connected to the SIEM.
Inspect Cloud Armor security policy logs on the internal backend services, check enforcedSecurityPolicy attributes, and run BigQuery scheduled queries to notify the SIEM.
Query Cloud NAT logging to extract threat signature payloads, and schedule a daily Cloud Storage Transfer Service job to push the logs to the SIEM.
Enable VPC Flow Logs on all subnetworks, filter for TCP connection reset flags in Cloud Monitoring, and use Cloud Functions to trigger hourly webhook alerts to the external SIEM.
Query Cloud NGFW threat logs in Cloud Logging to evaluate threat_id, application_name, and action in the jsonPayload, and configure a filtered Log Router sink streaming to a Pub/Sub topic connected to the SIEM.
Cloud NGFW Enterprise integrates Layer 7 application inspection (AppID) and Intrusion Prevention Service (IPS) powered by security signatures. When IPS endpoints inspect decrypted network sessions, deep-packet inspection logs are generated and written to Cloud Logging under the Cloud NGFW resource type, recording detailed application-layer metadata and security enforcement actions.
jsonPayload.action field (such as ALERT, DENY, or DROP), confirming whether the security profile blocked the exploit or operated in detection-only mode.jsonPayload contains dedicated fields including threat_id, threat_category, threat_severity, and application_name (or app_id), providing immediate visibility into evasive Layer 7 protocols.Cloud NGFW threat logs uniquely deliver inline Layer 7 and IPS signature metadata. Streaming these structured events via Log Router sinks to Pub/Sub is Google Cloud's recommended architecture for event-driven SecOps integration.
Inspect Cloud Armor security policy logs on the internal backend services, check enforcedSecurityPolicy attributes, and run BigQuery scheduled queries to notify the SIEM.