Professional Cloud Security EngineerConfiguring network securityMedium
A security team needs to monitor and analyze all inbound and outbound network traffic to and from their Compute Engine instances to detect anomalies and potential security threats. They require detailed flow information, including source/destination IP, ports, protocols, and byte counts, for forensic analysis and compliance. Which Google Cloud feature should they enable on their VPC subnets?
- ACloud Audit Logs
- BCloud Firewall Rules Logging
- CNetwork Intelligence Center
- DVPC Flow Logs
Show answer & explanationAnswer & explanation
Correct answer: D. VPC Flow Logs
VPC Flow Logs record network flow information for VM instances, capturing details like source/destination IP, ports, protocols, and byte counts, which is crucial for network monitoring, anomaly detection, and forensic analysis.
Why the other options are wrong
- A. Cloud Audit Logs record administrative and data access activities, not network flow data.
- B. Cloud Firewall Rules Logging only records when firewall rules are matched, not comprehensive network flow details.
- C. Network Intelligence Center provides network insights and topology, but VPC Flow Logs is the source of the raw flow data.
VPC Flow Logs
VPC Flow Logs record a sample of network flows sent from and received by VM instances in a subnet, providing detailed traffic information.
- Records network flow data (IPs, ports, protocols)
- Enabled per subnet
- Useful for security analysis, troubleshooting, compliance
Memory trick: Flow logs are like a traffic cop's detailed report of every car.