Professional Cloud Security EngineerConfiguring network securityHard
A security engineer is reviewing the firewall configuration for a critical application in Google Cloud. They notice a firewall rule with a priority of 1000 that allows all ingress TCP traffic on port 22 (SSH) from `0.0.0.0/0` to instances with a specific network tag. There's another rule with a priority of 500 that denies all ingress TCP traffic on port 22 from `0.0.0.0/0` to the same network tag. What is the effective outcome for SSH access to these instances?
- ASSH access will be allowed because the 'allow' rule has a lower priority number.
- BThe behavior is undefined due to conflicting rules, requiring manual intervention.
- CSSH access will be denied because the 'deny' rule has a higher priority.
- DSSH access will be allowed because allow rules always override deny rules.
Show answer & explanationAnswer & explanation
Correct answer: C. SSH access will be denied because the 'deny' rule has a higher priority.
Google Cloud firewall rules are evaluated based on their priority, where lower numbers indicate higher priority. In this scenario, the 'deny' rule with priority 500 takes precedence over the 'allow' rule with priority 1000, effectively denying SSH access.
Why the other options are wrong
- A. This is incorrect. Lower priority numbers mean higher priority in Google Cloud firewall rules.
- B. The behavior is well-defined by the priority system; it's not undefined.
- D. This is incorrect. Priority determines precedence, not the action type (allow/deny).
GCP Firewall Rule Priority
A numerical value (0-65535) assigned to Google Cloud firewall rules that determines their evaluation order.
- Lower priority numbers indicate higher precedence (e.g., 500 is higher than 1000)
- Rules are evaluated in order of priority, from lowest number to highest
- The first rule that matches the traffic and has the highest priority is applied
Memory trick: Lower number, higher power in firewall rules.