Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise is architecting a mission-critical, three-tier application (Web, Application, and Database tiers) across dedicated subnets within a Google Cloud Shared VPC. The central security team requires strict boundary segmentation with the following requirements:
Which network security design should the enterprise implement to satisfy these requirements?
Configure Google Cloud Armor security policies attached directly to tier subnets and expose intermediate tiers using Private Service Connect endpoints.
Implement hierarchical firewall policies at the organization or folder level using Resource Manager secure tags and service account identities to restrict ingress between adjacent tiers.
Deploy each application tier into separate VPC networks connected via VPC Network Peering with static route next-hops targeting internal passthrough Network Load Balancers.
Apply VPC-level firewall rules using legacy network tags on Compute Engine instances to restrict ingress and egress between tier subnets.
Configure Google Cloud Armor security policies attached directly to tier subnets and expose intermediate tiers using Private Service Connect endpoints.
Implement hierarchical firewall policies at the organization or folder level using Resource Manager secure tags and service account identities to restrict ingress between adjacent tiers.
Hierarchical firewall policies allow security administrators to define and enforce consistent firewall rules across the entire resource hierarchy (organization, folders, and projects) in Google Cloud. When combined with Resource Manager secure tags and service account identities, access control is bound directly to verified identity and governed metadata rather than mutable network properties or legacy network tags.
tagKeys/env/tagValues/web tag), ensuring strict east-west segmentation.roles/resourcemanager.tagUser). Workload administrators with compute instance edit permissions cannot add or remove secure tags unless explicitly granted tag administration rights, preventing unauthorized privilege escalation or boundary bypass.This solution provides tamper-proof, centrally administered boundary protection that couples identity-aware filtering with hierarchical policy controls, preventing lateral movement without requiring complex routing topologies or external appliances.
Deploy each application tier into separate VPC networks connected via VPC Network Peering with static route next-hops targeting internal passthrough Network Load Balancers.
Apply VPC-level firewall rules using legacy network tags on Compute Engine instances to restrict ingress and egress between tier subnets.