certslothcertsloth
PCNE/Topic 05

Google Cloud / Professional

Network security and controlled egress

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Filter packets, protect apps, inspect egress.

Must remember

  • VPC firewall rules are stateful and use direction, protocol, ports, targets and sources/destinations. Hierarchical and network firewall policies add organization-wide structure; understand policy evaluation and delegation before migration.
  • Cloud NGFW Essentials/Standard/Enterprise expose different capabilities. Select threat intelligence or deeper inspection only when required; use supported secure tags/service-account targeting for segmentation rather than unmaintained IP lists.
  • Cloud Armor protects supported load-balanced traffic with WAF rules, rate limits and other protections. Edge/backend policy placement matters; tune SQLi/XSS rules in preview before blocking legitimate traffic.
  • Public Cloud NAT enables supported outbound connections for internal-only resources without accepting unsolicited inbound sessions. Monitor ports and address capacity; static versus dynamic port allocation affects scaling and exhaustion.
  • Secure Web Proxy applies supported outbound web controls. It is distinct from Cloud NAT address translation and from an inbound WAF.
  • Use supported multi-NIC appliances, policy-based routes or internal load-balancer next hops for inline inspection. Packet Mirroring copies traffic to collectors for out-of-band analysis; copies do not block the original flow.

Review details

Firewall selection depends on effective hierarchical, network and VPC policy evaluation, not simply the lowest number found anywhere. Within a rule model, direction, targets, matching source/destination, protocol and priority determine eligibility. Secure tags have an IAM-controlled governance model distinct from ordinary network tags; inventory labels are not automatically traffic selectors.

Cloud Armor rule preview helps assess WAF/rate/bot rules before enforcement. Supported Adaptive Protection and advanced DDoS capabilities depend on service/tier and traffic path. NAT port allocation or address exhaustion causes outbound failures even when firewall and route are valid; monitor dropped/error signals and per-VM port use.

Choose under exam pressure

Requirement Choice and reason
Stop abusive HTTP requests Cloud Armor policy on the supported load balancer, tuned to the traffic.
Inspect a copy without changing forwarding Packet Mirroring with an appropriately sized collector.

Traps

  • Cloud NAT is not an inbound firewall-opening mechanism.
  • An out-of-band collector cannot block packets merely by observing them.

Active recall

1. What is a NAT exhaustion symptom?

New outbound connections fail while existing traffic may continue; inspect port allocation and errors.

2. Why preview WAF rules?

To measure false positives before enforcing blocks.

3. What is the purpose of secure tags?

Governed identity-like resource grouping for supported firewall policy targeting.

4. Does a route permit traffic through a firewall?

No; routing and policy must both allow the path.

5. Why ensure symmetric appliance paths?

Stateful inspection can fail when request and response traverse different uncoordinated state.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.