Google Cloud Digital LeaderSecurity and operations with Google CloudEasy

A financial institution is migrating its on-premises applications to Google Cloud. They have a strict compliance requirement to ensure that all network traffic between virtual machines (VMs) within their Virtual Private Cloud (VPC) network is inspected for potential threats and unauthorized access. Which Google Cloud security service should they implement to meet this requirement?

  1. ACloud Armor
  2. BSecurity Command Center
  3. CCloud Firewall
  4. DVPC Service Controls
Show answer & explanation

Correct answer: C. Cloud Firewall

Cloud Firewall (formerly VPC Firewall Rules) allows you to define granular rules to control ingress and egress traffic for VMs within a VPC network, which is essential for internal traffic inspection and threat prevention.

Why the other options are wrong

  • A. Cloud Armor is a DDoS protection and WAF service, primarily for external-facing applications.
  • B. Security Command Center is a centralized security management and risk platform, not a direct network traffic inspection tool.
  • D. VPC Service Controls help prevent data exfiltration by creating security perimeters around resources.

Cloud Firewall

Cloud Firewall provides stateful firewall rules for your Virtual Private Cloud (VPC) network, allowing you to control traffic to and from your virtual machine (VM) instances.

  • Operates at Layer 4 (TCP/UDP) and Layer 3 (IP).
  • Rules can be ingress (incoming) or egress (outgoing).
  • Can filter by IP range, protocol, ports, and service accounts/tags.

Memory trick: Firewalls Guard VPC Traffic Internally.

More Security and operations with Google Cloud questions