ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 66 - Professional Cloud Network Engineer discussion

Report
Export

You have created a firewall with rules that only allow traffic over HTTP, HTTPS, and SSH ports. Whiletesting, you specifically try to reach the server over multiple ports and protocols; however, you donot see any denied connections in the firewall logs. You want to resolve the issue.

What should you do?

A.
Enable logging on the default Deny Any Firewall Rule.
Answers
A.
Enable logging on the default Deny Any Firewall Rule.
B.
Enable logging on the VM Instances that receive traffic.
Answers
B.
Enable logging on the VM Instances that receive traffic.
C.
Create a logging sink forwarding all firewall logs with no filters.
Answers
C.
Create a logging sink forwarding all firewall logs with no filters.
D.
Create an explicit Deny Any rule and enable logging on the new rule.
Answers
D.
Create an explicit Deny Any rule and enable logging on the new rule.
Suggested answer: D

Explanation:

https://cloud.google.com/vpc/docs/firewall-rules-logging#egress_deny_example

You can only enable Firewall Rules Logging for rules in a Virtual Private Cloud (VPC) network. Legacy networks are not supported. Firewall Rules Logging only records TCP and UDP connections. Although you can create a firewall rule applicable to other protocols, you cannot log their connections. You cannot enable Firewall Rules Logging for the implied deny ingress and implied allow egress rules. Log entries are written from the perspective of virtual machine (VM) instances. Log entries are only created if a firewall rule has logging enabled and if the rule applies to traffic sent to or from the VM.

Entries are created according to the connection logging limits on a best effort basis. The number of connections that can be logged in a given interval is based on the machine type. Changes to firewall rules can be viewed in VPC audit logs. https://cloud.google.com/vpc/docs/firewall-ruleslogging#specifications

asked 18/09/2024
Justin Whelan
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first