ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 52 - Professional Cloud Network Engineer discussion

Report
Export

Your company offers a popular gaming service. Your instances are deployed with private IP addresses, and external access is granted through a global load balancer. You have recently engaged a traffic-scrubbing service and want to restrict your origin to allow connections only from the trafficscrubbing service.

What should you do?

A.
Create a Cloud Armor Security Policy that blocks all traffic except for the traffic-scrubbing service.
Answers
A.
Create a Cloud Armor Security Policy that blocks all traffic except for the traffic-scrubbing service.
B.
Create a VPC Firewall rule that blocks all traffic except for the traffic-scrubbing service.
Answers
B.
Create a VPC Firewall rule that blocks all traffic except for the traffic-scrubbing service.
C.
Create a VPC Service Control Perimeter that blocks all traffic except for the traffic-scrubbing service.
Answers
C.
Create a VPC Service Control Perimeter that blocks all traffic except for the traffic-scrubbing service.
D.
Create IPTables firewall rules that block all traffic except for the traffic-scrubbing service.
Answers
D.
Create IPTables firewall rules that block all traffic except for the traffic-scrubbing service.
Suggested answer: A

Explanation:

Global load balancer will proxy the connection . thus no trace of session origin IP. you should use Cloud Armor to geofence your service.

https://cloud.google.com/load-balancing/docs/https

asked 18/09/2024
xingrui li
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first