Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A security operations team is investigating suspicious lateral movement within a Google Cloud VPC. The incident response policy requires capturing and analyzing raw packet payloads (Layer 3 through Layer 7)—including full application data—from specific production Compute Engine instances hosting sensitive database workloads.
The capture architecture must meet the following requirements:
Which solution should the team implement?
Configure a Packet Mirroring policy targeting the production instances or subnets, and set the collector destination to an internal passthrough Network Load Balancer forwarding rule configured with the packet mirroring collector option.
Enable VPC Flow Logs on the subnet with an aggregation interval of 5 seconds, a 100% sampling rate, and write the telemetry to a Cloud Logging log bucket for BigQuery analysis.
Deploy an Apigee Message Logging policy on an Internal Application Load Balancer to capture raw TCP and UDP packet payloads into a centralized SIEM.
Create an egress Firewall Rules Logging rule on the database subnet, route the logs through a Pub/Sub topic, and ingest them into a Cloud IDS collector instance.
Configure a Packet Mirroring policy targeting the production instances or subnets, and set the collector destination to an internal passthrough Network Load Balancer forwarding rule configured with the packet mirroring collector option.
Google Cloud Packet Mirroring clones full Layer 3 through Layer 7 network traffic (both ingress and egress) directly from the virtual machine's virtual network interface (vNIC) at the Andromeda virtualization layer. It sends an exact copy of the traffic out-of-band to an internal passthrough Network Load Balancer without modifying, slowing down, or terminating the production packet stream.
--is-mirroring-collector. The load balancer distributes the mirrored traffic across an autoscaled backend instance group of collector appliances.This architecture provides enterprise-grade, native network packet capture. It completely decouples security monitoring from production traffic flow, ensuring forensic-level packet visibility with automatic failover and scalability.
Enable VPC Flow Logs on the subnet with an aggregation interval of 5 seconds, a 100% sampling rate, and write the telemetry to a Cloud Logging log bucket for BigQuery analysis.
Deploy an Apigee Message Logging policy on an Internal Application Load Balancer to capture raw TCP and UDP packet payloads into a centralized SIEM.
Create an egress Firewall Rules Logging rule on the database subnet, route the logs through a Pub/Sub topic, and ingest them into a Cloud IDS collector instance.