Google
PROFESSIONAL-CLOUD-NETWORK-ENGINEER · Question #65
Your company offers a popular gaming service. Your instances are deployed with private IP addresses, and external access is granted through a global load balancer. You believe you have identified a…
The correct answer is B. Create a Cloud Armor Policy rule that denies traffic, enable preview mode, and review necessary. You can log the requests by Client IP, and Preview Mode will not cause disruption to anyone, while you investigate. https://cloud.google.com/armor/docs/security-policy-concepts#preview_mode
Submitted by haru.x· Apr 18, 2026Implementing network security
Question
Your company offers a popular gaming service. Your instances are deployed with private IP addresses, and external access is granted through a global load balancer. You believe you have identified a potential malicious actor, but aren't certain you have the correct client IP address. You want to identify this actor while minimizing disruption to your legitimate users. What should you do?
Options
- ACreate a Cloud Armor Policy rule that denies traffic and review necessary logs.
- BCreate a Cloud Armor Policy rule that denies traffic, enable preview mode, and review necessary
- CCreate a VPC Firewall rule that denies traffic, enable logging and set enforcement to disabled,
- DCreate a VPC Firewall rule that denies traffic, enable logging and set enforcement to enabled,
How the community answered
(46 responses)- A2% (1)
- B80% (37)
- C11% (5)
- D7% (3)
Explanation
You can log the requests by Client IP, and Preview Mode will not cause disruption to anyone, while you investigate. https://cloud.google.com/armor/docs/security-policy-concepts#preview_mode
Topics
#Cloud Armor#WAF Preview Mode#Network Security#Global Load Balancer
Community Discussion
No community discussion yet for this question.