nerdexam
Google

PROFESSIONAL-CLOUD-NETWORK-ENGINEER · Question #229

Your organization deployed a mission critical application that is expected to be a new revenue source. As part of the planning and deployment process, you have recently implemented a security…

The correct answer is C. For all severity options (critical, high, medium, low and informational) in the security profile. To enhance the security posture of your mission-critical application and ensure that threats are logged and the related packets are dropped, you need to configure the security profile in Cloud NGFW to take a more aggressive action for all detected threats: 1. Override default…

Submitted by ashley.k· Apr 18, 2026Implementing network security

Question

Your organization deployed a mission critical application that is expected to be a new revenue source. As part of the planning and deployment process, you have recently implemented a security profile with the default set of threat signatures provided by Cloud Next Generation Firewall (Cloud NGFW). This application is the only application running on this project. You need to increase the security posture of the application to log the threat and drop the related packets. What should you do?

Options

  • AConfigure a new default threat signature with Deny All to all severity options. Review the logs to
  • BSet up a Linux VM as the frontend gateway for the application. Create iptables rules to drop all
  • CFor all severity options (critical, high, medium, low and informational) in the security profile,
  • DConfigure Cloud Scheduler to run a task that checks the Cloud NGFW logs to verify the threats.

How the community answered

(55 responses)
  • A
    2% (1)
  • B
    4% (2)
  • C
    85% (47)
  • D
    9% (5)

Explanation

To enhance the security posture of your mission-critical application and ensure that threats are logged and the related packets are dropped, you need to configure the security profile in Cloud NGFW to take a more aggressive action for all detected threats: 1. Override default actions in the security profile: By changing the default action for all severity levels (critical, high, medium, low, and informational) to Deny, you ensure that any threat matching a Cloud NGFW threat signature is logged and that the associated packets are dropped. 2. Threat logging: Cloud NGFW automatically logs all detected threats, including dropped packets. This provides visibility into potential attacks and allows you to monitor and analyze threats This approach ensures that your application is protected from known threats while providing detailed logs for auditing and further analysis, which aligns with the organization's goal of maintaining a high-security posture for a mission-critical application.

Topics

#Cloud NGFW#Threat Signatures#Security Profiles#Firewall Actions

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-NETWORK-ENGINEER Practice