Professional Cloud Security EngineerConfiguring network securityHard

A security engineer is tasked with configuring firewall rules for a new application deployed on Google Compute Engine. The application uses a custom TCP port 8443 for its backend service and needs to be accessible only from a specific set of IP addresses belonging to the internal corporate network (192.168.10.0/24). Additionally, all outbound traffic from the application VMs should be allowed, except for traffic to known malicious IP ranges, which must be explicitly denied. Which firewall rule configuration will achieve these requirements?

  1. AIngress allow rule: target tag 'app-backend', source range '192.168.10.0/24', TCP:8443. Egress deny rule: target tag 'app-backend', destination ranges 'malicious-ips', all protocols. Egress allow rule: target tag 'app-backend', destination ranges '0.0.0.0/0', all protocols, priority lower than deny rule.
  2. BIngress allow rule: target tag 'app-backend', source range '192.168.10.0/24', TCP:8443. Egress deny rule: target tag 'app-backend', destination ranges 'malicious-ips', all protocols, priority higher than allow rule. Egress allow rule: target tag 'app-backend', destination ranges '0.0.0.0/0', all protocols.
  3. CIngress allow rule: target tag 'app-backend', source range '192.168.10.0/24', TCP:8443. Egress deny rule: target tag 'app-backend', destination ranges 'malicious-ips', all protocols, priority lower than allow rule. Egress allow rule: target tag 'app-backend', destination ranges '0.0.0.0/0', all protocols.
  4. DIngress allow rule: target tag 'app-backend', source range '192.168.10.0/24', TCP:8443. Egress allow rule: target tag 'app-backend', destination ranges '0.0.0.0/0', all protocols, priority higher than deny rule. Egress deny rule: target tag 'app-backend', destination ranges 'malicious-ips', all protocols.
Show answer & explanation

Correct answer: B. Ingress allow rule: target tag 'app-backend', source range '192.168.10.0/24', TCP:8443. Egress deny rule: target tag 'app-backend', destination ranges 'malicious-ips', all protocols, priority higher than allow rule. Egress allow rule: target tag 'app-backend', destination ranges '0.0.0.0/0', all protocols.

Google Cloud firewall rules are processed by priority, with lower numbers having higher priority. To explicitly deny traffic to malicious IPs while generally allowing all other outbound traffic, the deny rule must have a higher priority (lower number) than the general allow-all rule. The ingress rule is straightforward.

Why the other options are wrong

  • A. This option incorrectly places the egress deny rule with a priority lower than the general allow rule, meaning the allow rule would take precedence.
  • C. This option incorrectly places the egress deny rule with a priority lower than the general allow rule, meaning the allow rule would take precedence.
  • D. This option incorrectly states that the allow rule has higher priority than the deny rule, which would allow traffic to malicious IPs.

GCP Firewall Rule Priority

Google Cloud firewall rules are evaluated by priority, with rules having numerically lower priority values taking precedence over rules with higher priority values.

  • Priority is a number from 0 to 65535 (default 1000).
  • Lower numbers mean higher priority (evaluated first).
  • If two rules conflict, the one with the higher priority (lower number) wins.

Memory trick: Lower number, higher power; Deny beats Allow if higher priority.

More Configuring network security questions