🔥 3-day streak
Google Cloud Professional Cloud Network Engineer84 / 142
Question 84 of 142

A financial services company uses a Google Cloud organization with three folders: 'prod', 'dev', and 'shared-services'. The central security team must enforce a non-overridable rule that blocks all inbound RDP (TCP 3389) traffic to every VPC in the organization, while allowing individual project teams to still define their own additional allow/deny rules for other ports. The security team also wants a separate rule in the 'dev' folder that permits SSH (TCP 22) from the corporate CIDR range, but this rule should be evaluatable by lower-level project rules if they choose to override. Which design meets these requirements?

Reviewed for accuracy · Report an issueNext question