Professional Cloud Security EngineerConfiguring network securityMedium

A security team needs to monitor and analyze all inbound and outbound network traffic to and from virtual machines in a specific VPC network for security auditing and compliance purposes. They require detailed metadata about each connection, including source/destination IP, ports, protocols, and byte counts. The solution must be scalable and integrated with Google Cloud's logging and monitoring tools. Which Google Cloud networking feature should they enable?

  1. AVPC Flow Logs
  2. BCloud Audit Logs
  3. CNetwork Intelligence Center
  4. DCloud NAT logs
Show answer & explanation

Correct answer: A. VPC Flow Logs

VPC Flow Logs record network flow information for all VM instances in a VPC network. They capture critical metadata like source/destination IP, ports, protocols, byte counts, and more, making them ideal for security auditing, network forensics, and compliance.

Why the other options are wrong

  • B. Cloud Audit Logs record administrative activities and data access, not network traffic flow details.
  • C. Network Intelligence Center provides network health monitoring and diagnostics, but VPC Flow Logs are the source for detailed traffic records.
  • D. Cloud NAT logs provide information about NAT translations, not comprehensive network flow data for all VMs.

VPC Flow Logs

A Google Cloud feature that records network flow information for VM instances within a VPC network.

  • Captures metadata like source/destination IP, ports, protocols, byte counts
  • Useful for network monitoring, forensics, security auditing, and compliance
  • Can be exported to Cloud Logging, BigQuery, or Cloud Storage

Memory trick: See every packet, know every flow.

More Configuring network security questions