nerdexam
Google

PROFESSIONAL-CLOUD-NETWORK-ENGINEER · Question #210

You have recently taken over responsibility for your organization's Google Cloud network security configurations. You want to review your Cloud Next Generation Firewall (Cloud NGFW) configurations…

The correct answer is B. Enable "Overly permissive rules insights" in Firewall Insights. Review results for rules that show. Firewall Insights in Google Cloud provides a feature called "Overly permissive rules insights," which automatically identifies and highlights firewall rules that allow excessive or broad access, such as ingress traffic from 0.0.0.0/0 (all internet sources). By enabling this…

Submitted by yasin.bd· Apr 18, 2026Implementing network security

Question

You have recently taken over responsibility for your organization's Google Cloud network security configurations. You want to review your Cloud Next Generation Firewall (Cloud NGFW) configurations and ensure there are no rules that are allowing ingress traffic to your VMs and services from the internet. You want to avoid manual work. What should you do?

Options

  • AReview the firewall policy rules associated with the VPC, and filter for rules that allow ingress
  • BEnable "Overly permissive rules insights" in Firewall Insights. Review results for rules that show
  • CRun Connectivity Tests from multiple external sources to double-check ingress traffic settings.
  • DEnable the Network Analyzer API and review the "VPC Network" category insights.

How the community answered

(52 responses)
  • A
    4% (2)
  • B
    73% (38)
  • C
    17% (9)
  • D
    6% (3)

Explanation

Firewall Insights in Google Cloud provides a feature called "Overly permissive rules insights," which automatically identifies and highlights firewall rules that allow excessive or broad access, such as ingress traffic from 0.0.0.0/0 (all internet sources). By enabling this feature, you can quickly and efficiently identify rules that could pose security risks, such as those allowing unauthorized ingress traffic to your VMs and services from the internet. This approach avoids the need for manual inspection and ensures that you have a comprehensive view of potential security issues in your network configuration.

Topics

#Cloud NGFW#Firewall Insights#Network Security#Security Policy Review

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-NETWORK-ENGINEER Practice