nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #131

Your company requires the security and network engineering teams to identify all network anomalies within and across VPCs, internal traffic from VMs to VMs, traffic between end locations on the…

The correct answer is C. Enable VPC Flow Logs on the subnet. VPC Flow Logs samples each VM's TCP, UDP, ICMP, ESP, and GRE flows. Both inbound and outbound flows are sampled. These flows can be between the VM and another VM, a host in your on-premises data center, a Google service, or a host on the internet…

Submitted by tom_us· Apr 18, 2026Configuring network security

Question

Your company requires the security and network engineering teams to identify all network anomalies within and across VPCs, internal traffic from VMs to VMs, traffic between end locations on the internet and VMs, and traffic between VMs to Google Cloud services in production. Which method should you use?

Options

  • ADefine an organization policy constraint.
  • BConfigure packet mirroring policies.
  • CEnable VPC Flow Logs on the subnet.
  • DMonitor and analyze Cloud Audit Logs.

How the community answered

(18 responses)
  • A
    17% (3)
  • B
    6% (1)
  • C
    72% (13)
  • D
    6% (1)

Explanation

VPC Flow Logs samples each VM's TCP, UDP, ICMP, ESP, and GRE flows. Both inbound and outbound flows are sampled. These flows can be between the VM and another VM, a host in your on-premises data center, a Google service, or a host on the internet. https://cloud.google.com/vpc/docs/flow-logs

Topics

#VPC Flow Logs#Network Monitoring#Network Anomaly Detection#Network Security

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice