nerdexam
Google

PROFESSIONAL-CLOUD-NETWORK-ENGINEER · Question #111

In your Google Cloud organization, you have two folders: Dev and Prod. You want a scalable and consistent way to enforce the following firewall rules for all virtual machines (VMs) with minimal…

The correct answer is A. Create and associate a firewall policy with the Dev folder with a rule to open port 8080. Create. https://cloud.google.com/vpc/docs/firewall-policies-overview

Submitted by kim_seoul· Apr 18, 2026Implementing network security

Question

In your Google Cloud organization, you have two folders: Dev and Prod. You want a scalable and consistent way to enforce the following firewall rules for all virtual machines (VMs) with minimal cost: Port 8080 should always be open for VMs in the projects in the Dev folder. Any traffic to port 8080 should be denied for all VMs in your projects in the Prod folder. What should you do?

Options

  • ACreate and associate a firewall policy with the Dev folder with a rule to open port 8080. Create
  • BCreate a Shared VPC for the Dev projects and a Shared VPC for the Prod projects. Create a VPC
  • CIn all VPCs for the Dev projects, create a VPC firewall rule to open port 8080. In all VPCs for the
  • DUse Anthos Config Connector to enforce a security policy to open port 8080 on the Dev VMs and

How the community answered

(48 responses)
  • A
    71% (34)
  • B
    10% (5)
  • C
    15% (7)
  • D
    4% (2)

Explanation

https://cloud.google.com/vpc/docs/firewall-policies-overview

Topics

#Hierarchical Firewall Policies#Network Security#Folder-level Enforcement#Scalable Network Policies

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-NETWORK-ENGINEER Practice