ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 37 - Professional Cloud Network Engineer discussion

Report
Export

Your company is running out of network capacity to run a critical application in the on-premises data center. You want to migrate the application to GCP. You also want to ensure that the Security team does not lose their ability to monitor traffic to and from Compute Engine instances.

Which two products should you incorporate into the solution? (Choose two.)

A.
VPC flow logs
Answers
A.
VPC flow logs
B.
Firewall logs
Answers
B.
Firewall logs
C.
Cloud Audit logs
Answers
C.
Cloud Audit logs
D.
Stackdriver Trace
Answers
D.
Stackdriver Trace
E.
Compute Engine instance system logs
Answers
E.
Compute Engine instance system logs
Suggested answer: A, B

Explanation:

A: Using VPC Flow Logs VPC Flow Logs records a sample of network flows sent from and received by VM instances, including instances used as GKE nodes. These logs can be used for network monitoring, forensics, real-time security analysis, and expense optimization.

https://cloud.google.com/vpc/docs/using-flow-logs (B): Firewall Rules Logging overview Firewall Rules Logging allows you to audit, verify, and analyze the effects of your firewall rules. For example, you can determine if a firewall rule designed to deny traffic is functioning as intended. Firewall Rules Logging is also useful if you need to determine how many connections are affected by a given firewall rule. You enable Firewall Rules Logging individually for each firewall rule whose connections you need to log. Firewall Rules Logging is an option for any firewall rule, regardless of the action (allow or deny) or direction (ingress or egress) of the rule.

https://cloud.google.com/vpc/docs/firewall-rules-logging

asked 18/09/2024
Cornelia Bauer
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first