Google Associate Cloud EngineerEnsuring successful operation of a cloud solutionEasy

A security auditor needs to ensure that all network traffic between Compute Engine instances within a specific Virtual Private Cloud (VPC) network is explicitly denied by default, and only allowed traffic is permitted based on least privilege. Which VPC networking component should be configured to enforce this policy effectively?

  1. AVPC Service Controls
  2. BShared VPC
  3. CFirewall rules
  4. DCloud VPN
Show answer & explanation

Correct answer: C. Firewall rules

VPC firewall rules allow you to control traffic to and from your Compute Engine instances. By default, all ingress traffic is denied, and all egress traffic is allowed. You can create rules to explicitly allow specific ingress and egress traffic, enforcing a least privilege model.

Why the other options are wrong

  • A. VPC Service Controls help mitigate data exfiltration risks by creating security perimeters around Google Cloud resources, but they don't manage instance-level network traffic flow directly via allow/deny rules.
  • B. Shared VPC allows multiple projects to use a common VPC network, but it doesn't directly enforce traffic denial/allowance policies at the instance level.
  • D. Cloud VPN connects on-premises networks to Google Cloud VPCs, but it doesn't control traffic between instances within the VPC itself.

VPC Firewall Rules

Network rules that control ingress and egress traffic to and from Compute Engine instances within a Virtual Private Cloud (VPC) network.

  • Stateless, applied at the instance level
  • Default deny for ingress, default allow for egress
  • Can specify source/destination, protocols, ports, and targets

Memory trick: Firewall: Your network's bouncer, deciding who gets in or out.

More Ensuring successful operation of a cloud solution questions