Google Associate Cloud EngineerEnsuring successful operation of a cloud solutionMedium
A security team needs to monitor all ingress and egress traffic for Compute Engine instances within a specific subnet to detect anomalies and potential security threats. They want to capture metadata about network flows, such as source/destination IP, ports, and protocols, without installing agents on the VMs. Which Google Cloud logging feature should they enable?
- AVPC Flow Logs
- BStackdriver Trace
- CCloud Audit Logs
- DCloud Logging agent
Show answer & explanationAnswer & explanation
Correct answer: A. VPC Flow Logs
VPC Flow Logs record network flow metadata from VM instances, providing insights into network traffic patterns, security analysis, and troubleshooting, without requiring any agent installation on the VMs.
Why the other options are wrong
- B. Stackdriver Trace (now Cloud Trace) collects latency data from requests to monitor application performance, not network flow data.
- C. Cloud Audit Logs record administrative activities and data access, not network flow data.
- D. Cloud Logging agent collects logs from within the VM, which contradicts the requirement of not installing agents.
VPC Flow Logs
A feature that records a sample of network flows sent from and received by VM instances in your Virtual Private Cloud (VPC) network.
- Captures network flow metadata
- No agents required on VMs
- Useful for security analysis and network monitoring
Memory trick: Flow Logs show the network's secrets, without touching a VM.