Professional Cloud Security EngineerConfiguring network securityMedium

A company is migrating a legacy application to Google Cloud. The application requires a fixed set of external IP addresses to be allowed through its firewall for outbound connections to specific third-party APIs. The security team wants to define these allowed external IP addresses in a reusable and manageable way, ensuring consistency across multiple firewall rules and potentially different projects. Which Google Cloud networking feature should they use?

  1. ACustom Roles
  2. BNetwork Tags
  3. CService Accounts
  4. DIP Address Lists (in Network Firewall Policies)
Show answer & explanation

Correct answer: D. IP Address Lists (in Network Firewall Policies)

IP Address Lists within Network Firewall Policies allow you to define a group of IP addresses (or CIDR ranges) as a named object. This object can then be referenced by multiple firewall rules, making it reusable and centralizing the management of these addresses.

Why the other options are wrong

  • A. Custom Roles define granular permissions for IAM, not for grouping IP addresses for network security rules.
  • B. Network Tags are used to identify VM instances for firewall rules, not for defining groups of external IP addresses.
  • C. Service Accounts are identities for applications and services, used for authorization, not for managing external IP address lists for firewall rules.

IP Address Lists (Network Firewall Policies)

A feature within Google Cloud Network Firewall Policies that allows defining named collections of IP addresses or CIDR ranges for reusable use in firewall rules.

  • Centralizes management of IP addresses.
  • Ensures consistency across multiple firewall rules.
  • Can be used for both source and destination IP addresses.

Memory trick: IP Address Lists are like a VIP guest list for your firewall, easily updated and shared.

More Configuring network security questions