Professional Cloud Security EngineerConfiguring network securityEasy
A company is deploying a new web application on Google Cloud and needs to ensure that only traffic from specific trusted IP addresses can access the backend servers. They also want to restrict outbound traffic from these servers to only necessary services. How should a security engineer configure this using Google Cloud's networking services?
- AUse Cloud Armor for inbound filtering and VPC Service Controls for outbound filtering.
- BConfigure ingress firewall rules to allow trusted IPs and egress firewall rules to restrict outbound access.
- CApply network tags to the backend servers and use Cloud CDN to filter traffic.
- DImplement Private Service Connect for inbound access and a NAT Gateway for outbound restrictions.
Show answer & explanationAnswer & explanation
Correct answer: B. Configure ingress firewall rules to allow trusted IPs and egress firewall rules to restrict outbound access.
Google Cloud firewall rules operate at the VPC network level and can specify both ingress (inbound) and egress (outbound) traffic policies based on IP ranges, protocols, and ports, which directly addresses the requirements.
Why the other options are wrong
- A. Cloud Armor is for DDoS protection and WAF, not general inbound IP filtering for backends. VPC Service Controls are for data exfiltration prevention, not outbound network access control.
- C. Network tags are used with firewall rules to identify instances, but Cloud CDN is for content delivery, not traffic filtering.
- D. Private Service Connect is for consuming managed services or publishing services across VPCs, not for general inbound IP filtering. NAT Gateway is for instances without external IPs to access the internet, not for restricting outbound traffic to specific services.
GCP Firewall Rules
Rules that allow or deny traffic to and from Google Cloud instances based on specified configurations.
- Operate at the VPC network level
- Can be configured for ingress (inbound) or egress (outbound) traffic
- Parameters include IP ranges, protocols, ports, and network tags/service accounts
Memory trick: Traffic lights for your cloud network.