Professional Cloud Security EngineerConfiguring network securityMedium
A security team needs to monitor and analyze all inbound and outbound network traffic to and from virtual machines in a specific VPC network for security auditing and compliance purposes. They require detailed metadata about each connection, including source/destination IP, ports, protocols, and byte counts. The solution must be scalable and integrated with Google Cloud's logging and monitoring tools. Which Google Cloud networking feature should they enable?
- AVPC Flow Logs
- BCloud Audit Logs
- CNetwork Intelligence Center
- DCloud NAT logs
Show answer & explanationAnswer & explanation
Correct answer: A. VPC Flow Logs
VPC Flow Logs record network flow information for all VM instances in a VPC network. They capture critical metadata like source/destination IP, ports, protocols, byte counts, and more, making them ideal for security auditing, network forensics, and compliance.
Why the other options are wrong
- B. Cloud Audit Logs record administrative activities and data access, not network traffic flow details.
- C. Network Intelligence Center provides network health monitoring and diagnostics, but VPC Flow Logs are the source for detailed traffic records.
- D. Cloud NAT logs provide information about NAT translations, not comprehensive network flow data for all VMs.
VPC Flow Logs
A Google Cloud feature that records network flow information for VM instances within a VPC network.
- Captures metadata like source/destination IP, ports, protocols, byte counts
- Useful for network monitoring, forensics, security auditing, and compliance
- Can be exported to Cloud Logging, BigQuery, or Cloud Storage
Memory trick: See every packet, know every flow.