exam questions

Exam Professional Cloud Security Engineer All Questions

View all questions & answers for the Professional Cloud Security Engineer exam

Exam Professional Cloud Security Engineer topic 1 question 114 discussion

Actual exam question from Google's Professional Cloud Security Engineer
Question #: 114
Topic #: 1
[All Professional Cloud Security Engineer Questions]

You recently joined the networking team supporting your company's Google Cloud implementation. You are tasked with familiarizing yourself with the firewall rules configuration and providing recommendations based on your networking and Google Cloud experience. What product should you recommend to detect firewall rules that are overlapped by attributes from other firewall rules with higher or equal priority?

  • A. Security Command Center
  • B. Firewall Rules Logging
  • C. VPC Flow Logs
  • D. Firewall Insights
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ExamQnA
Highly Voted 2 years ago
Selected Answer: D
Firewall Insights analyzes your firewall rules to detect firewall rules that are shadowed by other rules. A shadowed rule is a firewall rule that has all of its relevant attributes, such as its IP address and port ranges, overlapped by attributes from one or more rules with higher or equal priority, called shadowing rules. https://cloud.google.com/network-intelligence-center/docs/firewall-insights/concepts/overview
upvoted 6 times
...
zellck
Highly Voted 1 year, 8 months ago
Selected Answer: D
D is the answer. https://cloud.google.com/network-intelligence-center/docs/firewall-insights/concepts/overview#shadowed-firewall-rules Firewall Insights analyzes your firewall rules to detect firewall rules that are shadowed by other rules. A shadowed rule is a firewall rule that has all of its relevant attributes, such as its IP address and port ranges, overlapped by attributes from one or more rules with higher or equal priority, called shadowing rules.
upvoted 6 times
AzureDP900
1 year, 7 months ago
Agreed
upvoted 1 times
...
...
Xoxoo
Most Recent 9 months ago
Selected Answer: D
To detect firewall rules that are overlapped by attributes from other firewall rules with higher or equal priority, you can use Firewall Insights. Firewall Insights is a feature of Google Cloud that provides visibility to firewall rule usage metrics and automatic analysis on firewall rule misconfigurations. It allows you to improve your security posture by detecting overly permissive firewall rules, unused firewall rules, and overlapping firewall rules. With Firewall Insights, you can automatically detect rules that can’t be reached during firewall rule evaluation due to overlapping rules with higher priorities. You can also detect unnecessary allow rules, open ports, and IP ranges and remove them to tighten the security boundary.
upvoted 3 times
...
GCBC
9 months, 3 weeks ago
definitely D - https://cloud.google.com/network-intelligence-center/docs/firewall-insights/concepts/overview
upvoted 2 times
...
AzureDP900
1 year, 7 months ago
D. Firewall Insights
upvoted 2 times
...
AwesomeGCP
1 year, 8 months ago
Selected Answer: D
D. Firewall Insights
upvoted 2 times
...
mikesp
2 years ago
Selected Answer: D
Answer = D.
upvoted 1 times
...
mouchu
2 years, 1 month ago
Answer = D Firewall Insights analyzes your firewall rules to detect firewall rules that are shadowed by other rules.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...