Professional Cloud Security EngineerConfiguring network securityMedium
A security auditor needs to verify that no unauthorized external IP addresses can initiate connections to sensitive internal Virtual Machines (VMs) in a Google Cloud VPC network. The auditor wants a comprehensive view of all incoming traffic flows that were denied by firewall rules, including source IP, destination IP, port, and protocol, for a specific period. Which Google Cloud logging feature provides this information?
- ACloud Firewall Insights
- BCloud Audit Logs
- CNetwork Intelligence Center Connectivity Tests
- DVPC Flow Logs
Show answer & explanationAnswer & explanation
Correct answer: D. VPC Flow Logs
VPC Flow Logs record network flow information for IP traffic sent from and received by VM instances. They can be configured to capture denied traffic, providing detailed insights into source/destination IPs, ports, and protocols for security analysis.
Why the other options are wrong
- A. Cloud Firewall Insights helps optimize firewall rules but doesn't provide raw denied traffic logs for security auditing.
- B. Cloud Audit Logs record administrative activities and data access, not detailed network traffic flows.
- C. Network Intelligence Center Connectivity Tests verify network reachability but do not log actual traffic flows, especially denied ones.
VPC Flow Logs
VPC Flow Logs record a sample of network flows sent from and received by VM instances, providing visibility into network traffic patterns.
- Captures source/destination IP, port, protocol, bytes, packets.
- Can be configured to log accepted, denied, or all traffic.
- Useful for network monitoring, forensics, and security analysis.
Memory trick: Flow Logs show you the 'who, what, where' of your network traffic.