Professional Cloud Security EngineerConfiguring network securityMedium
A security team needs to restrict access to a critical internal web application hosted on Google Compute Engine. The application should only be accessible from a specific subnet (10.0.1.0/24) within the same VPC network and from a designated jump host (10.0.0.5) in another subnet. No other internal or external traffic should reach the application. Which firewall rule configuration approach should be used?
- ACreate an ingress allow rule with a source tag for 10.0.1.0/24 and a separate ingress allow rule for 10.0.0.5. No deny rules are needed.
- BCreate an ingress allow rule with source ranges 10.0.1.0/24 and 10.0.0.5/32. Ensure the application VMs have a target tag. All other traffic will be implicitly denied.
- CCreate two ingress allow rules: one for 10.0.1.0/24 and one for 10.0.0.5/32. Create an ingress deny rule for 0.0.0.0/0. All rules target the application VMs.
- DCreate an ingress deny rule for 0.0.0.0/0, then create an ingress allow rule with a higher priority for source ranges 10.0.1.0/24 and 10.0.0.5/32.
Show answer & explanationAnswer & explanation
Correct answer: B. Create an ingress allow rule with source ranges 10.0.1.0/24 and 10.0.0.5/32. Ensure the application VMs have a target tag. All other traffic will be implicitly denied.
Google Cloud VPC networks have an implicit deny ingress rule. Therefore, to restrict access, you only need to create specific ingress allow rules for the permitted sources. Any traffic not matching an allow rule will be implicitly denied.
Why the other options are wrong
- A. Using source tags for specific IP addresses is less direct than source ranges and still implies the need for precise allow rules, but the core issue is the redundancy of explicit denies.
- C. Creating an explicit ingress deny rule for 0.0.0.0/0 is redundant and unnecessary because of the implicit deny rule.
- D. While this approach technically works due to priority, it's unnecessarily complex. Relying on the implicit deny rule is simpler and standard practice.
GCP Implicit Firewall Rules
Every Google Cloud VPC network has two implicit firewall rules: an ingress deny all and an egress allow all.
- Implicit ingress deny: blocks all incoming connections by default.
- Implicit egress allow: permits all outgoing connections by default.
- User-created rules override implicit rules based on priority and specificity.
Memory trick: Ingress is implicitly denied; you must explicitly invite.