exam questions

Exam Professional Cloud Network Engineer All Questions

View all questions & answers for the Professional Cloud Network Engineer exam

Exam Professional Cloud Network Engineer topic 1 question 81 discussion

Actual exam question from Google's Professional Cloud Network Engineer
Question #: 81
Topic #: 1
[All Professional Cloud Network Engineer Questions]

Your company's security team tends to use managed services when possible. You need to build a dashboard to show the number of deny hits that occur against configured firewall rules without increasing operational overhead. What should you do?

  • A. Configure Firewall Rules Logging. Use Firewall Insights to display the number of hits.
  • B. Configure Firewall Rules Logging. View the logs in Cloud Logging, and create a custom dashboard in Cloud Monitoring to display the number of hits.
  • C. Configure a firewall appliance from the Google Cloud Marketplace. Route all traffic through this appliance, and apply the firewall rules at this layer. Use the firewall appliance to display the number of hits.
  • D. Configure Packet Mirroring on the VPC. Apply a filter with an IP address list of the Denied Firewall rules. Configure an intrusion detection system (IDS) appliance as the receiver to display the number of hits.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Komal697
Highly Voted 1 year, 7 months ago
Selected Answer: B
Option A is a valid approach, but it may increase operational overhead if you need to handle a large volume of logs or if you need to customize the display of the logs. Firewall Rules Logging captures firewall activity logs in real-time, and you can export these logs to other services like Cloud Storage, BigQuery, or Pub/Sub for further analysis. However, you would need to use another service like Firewall Insights to display the number of deny hits, which would require additional configuration and setup.
upvoted 6 times
Komal697
1 year, 7 months ago
Option B is a better solution because it provides greater flexibility in creating custom dashboards and reports for firewall rule activity logs. Cloud Logging provides a central location for storing, analyzing, and monitoring logs from multiple Google Cloud services, including firewall activity logs. With Cloud Monitoring, you can create custom dashboards and alerts based on the logs' data to monitor and track firewall rules' deny hits. In summary, both options are valid solutions, but option B offers greater flexibility and customization capabilities.
upvoted 3 times
...
...
AzureDP900
Highly Voted 1 year, 11 months ago
A is correct https://cloud.google.com/network-intelligence-center/docs/firewall-insights/concepts/overview
upvoted 5 times
...
mohitms1996
Most Recent 1 month ago
Selected Answer: A
Firewall Rules Logging is a managed service that logs all firewall rule hits in Cloud Logging. Firewall Insights (a feature of Google Cloud's Network Intelligence Center) analyzes firewall logs automatically and provides insights, including the number of deny hits. Minimal operational overhead since it’s a built-in GCP feature that does not require additional infrastructure. Why not the other options? B. Custom Cloud Monitoring dashboard: While possible, it requires manual setup in Cloud Monitoring, increasing operational overhead. Firewall Insights already provides this data automatically, making option A a more efficient choice.
upvoted 1 times
...
1f01b87
1 month, 2 weeks ago
Selected Answer: A
A is correct. https://cloud.google.com/network-intelligence-center/docs/firewall-insights/how-to/view-understand-insights#nic-viewing-deny-rules-24h
upvoted 1 times
...
desertlotus1211
8 months, 2 weeks ago
Answer is B: https://cloud.google.com/network-intelligence-center/docs/firewall-insights/how-to/view-metrics Look at the bottom of the page... "You can use Monitoring dashboards and their associated charts to visualize the data for the Firewall Insights metrics described in the preceding sections. To monitor these metrics in Monitoring, you can create custom dashboards. You can also add alerts based on these metrics."
upvoted 1 times
...
gonlafer
8 months, 2 weeks ago
Selected Answer: A
https://cloud.google.com/network-intelligence-center/docs/firewall-insights/how-to/view-understand-insights#nic-viewing-deny-rules-24h
upvoted 1 times
...
gcpengineer
1 year, 2 months ago
Selected Answer: A
Deny rules are covered by fw insights
upvoted 1 times
...
didek1986
1 year, 2 months ago
Selected Answer: B
A is missing dashboard
upvoted 4 times
...
rglearn
1 year, 3 months ago
Selected Answer: A
Technically both A & B are correct but as question demands to have a solution which has less overhead, I would go with Option A
upvoted 2 times
...
Andreyv
1 year, 3 months ago
Selected Answer: B
Answer A doesn't describe about creating a dashboard.
upvoted 4 times
...
mcjim
1 year, 5 months ago
Selected Answer: B
The correct answer is B as firewall insights doesn't show hits against DENY rules: https://cloud.google.com/network-intelligence-center/docs/firewall-insights/concepts/overview#insights
upvoted 4 times
...
mondigo
1 year, 7 months ago
B. Insights are good for recommendation no dashboards moreover Insight Overly permissive rule insights, including each of the following: Allow rules with no hits Allow rules that are unused based on trend analysis (preview) Allow rules with unused attributes Allow rules with overly permissive IP addresses or port ranges Deny rule insights with no hits during the observation period.
upvoted 2 times
mondigo
1 year, 7 months ago
A is correct, when you enable logging it is possible to see hits for deny rules as well
upvoted 1 times
...
...
exambott
1 year, 9 months ago
B. Firewall insights do not show the number of hits against a deny rule.
upvoted 2 times
...
pk349
1 year, 9 months ago
• A. Configure Firewall Rules Logging. Use Firewall Insights to display the number ***** of hits. With Firewall Insights metrics, you can perform the following tasks: • Verify that firewall rules are used in an intended way. • Over specified periods, verify that firewall rules allow or block their intended connections.
upvoted 1 times
...
ccieman2016
1 year, 11 months ago
Selected Answer: A
Letter A for me
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago