Examtopics

Professional Cloud Network Engineer
  • Topic 1 Question 188

    Your company uses Compute Engine instances that are exposed to the public internet. Each compute instance has a single network interface with a single public IP address. You need to block any connection attempt that originates from internet clients with IP addresses that belong to the BGP_ASN_TOBLOCK BGP ASN. What should you do?

    • Create a new Cloud Armor backend security policy, and use the --network-src-asns parameter.

    • Create a new Cloud Armor network edge security policy, and use the --network-src-asns parameter.

    • Create a new Cloud Armor edge security policy, and use the --network-src-asns parameter.

    • Create a new firewall policy ingress rule, and use the --network-src-asns parameter.


    シャッフルモード