🔥 3-day streak
Google Cloud Professional Cloud Network Engineer7 / 142
Question 7 of 142

Your security team wants to allow a large SaaS partner's published IP ranges to reach your global external Application Load Balancer while blocking all other source IPs. The partner distributes their egress ranges as a curated list that Google maintains and updates automatically. You must implement this in a Cloud Armor security policy with minimal ongoing maintenance and without exceeding rule limits from listing hundreds of individual CIDRs. Which approach should you use?

Reviewed for accuracy · Report an issueNext question