Professional Cloud Security EngineerEnsuring complianceHard

A company is migrating its legacy applications to Google Cloud, which includes a complex, multi-tier application with strict network segmentation requirements. They need to implement a security policy that allows traffic only on specific ports and protocols between different tiers (e.g., web tier to application tier, application tier to database tier) and explicitly denies all other traffic. This policy needs to be centrally managed and applied consistently across multiple GKE clusters and Compute Engine instances. Which Google Cloud capability should they leverage?

  1. AVPC Firewall Rules
  2. BNetwork Policy in GKE
  3. CCloud Armor security policies
  4. DHierarchical Firewall Policies
Show answer & explanation

Correct answer: D. Hierarchical Firewall Policies

Hierarchical Firewall Policies allow you to create and enforce consistent firewall rules across your entire organization, folders, and projects. This enables centralized management of network segmentation rules that apply to both Compute Engine instances and GKE clusters (via their underlying Compute Engine VMs), ensuring strict traffic control between application tiers, overriding or complementing VPC firewall rules at lower levels.

Why the other options are wrong

  • A. VPC Firewall Rules apply at the network level and can be overridden or complemented by hierarchical policies, but lack central management across an organization's folders/projects.
  • B. Network Policy in GKE applies specifically to Pod-to-Pod communication *within* a GKE cluster, not across different Compute Engine instances or between clusters/projects.
  • C. Cloud Armor security policies primarily protect applications from DDoS and web attacks (WAF functionality) at the edge, not for internal network segmentation between application tiers.

Hierarchical Firewall Policies

A Google Cloud capability that allows granular firewall rules to be defined and enforced at the organization or folder level, applying to all projects and resources beneath them.

  • Enables centralized network security management.
  • Rules inherit down the resource hierarchy.
  • Can override or complement VPC firewall rules.

Memory trick: Hierarchical Firewalls are the 'Master Plan' for network security, defining rules from the top down.

More Ensuring compliance questions