nerdexam
GoogleGoogle

PROFESSIONAL-CLOUD-NETWORK-ENGINEER · Question #220

PROFESSIONAL-CLOUD-NETWORK-ENGINEER Question #220: Real Exam Question with Answer & Explanation

Sign in or unlock PROFESSIONAL-CLOUD-NETWORK-ENGINEER to reveal the answer and full explanation for question #220. The question stem and answer options stay visible for context.

Submitted by kevin_r· Apr 18, 2026Implementing network security

Question

Your organization's security team recently discovered that there is a high risk of malicious activities originating from some of your VMs connected to the internet. These malicious activities are currently undetected when TLS communication is used. You must ensure that encrypted traffic to the internet is inspected. What should you do?

Options

  • AEnable Cloud Armor TLS inspection policy, and associate the policy with the backend VMs.
  • BUse Cloud NGFW Essentials. Create a firewall rule for egress traffic, and enable VPC Flow Logs
  • CConfigure a TLS agent on every VM to intercept TLS traffic before it reaches the internet.
  • DUse Cloud NGFW Enterprise. Create a firewall rule for egress traffic with the --tls-inspect flag,

Unlock PROFESSIONAL-CLOUD-NETWORK-ENGINEER to see the answer

You've previewed enough free PROFESSIONAL-CLOUD-NETWORK-ENGINEER questions. Unlock PROFESSIONAL-CLOUD-NETWORK-ENGINEER for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Network security#TLS inspection#Cloud NGFW Enterprise#Egress traffic inspection
Full PROFESSIONAL-CLOUD-NETWORK-ENGINEER PracticeBrowse All PROFESSIONAL-CLOUD-NETWORK-ENGINEER Questions