🔥 3-day streak
Google Cloud Professional Cloud Network Engineer98 / 142
Question 98 of 142

A security engineer manages a global network firewall policy in a Shared VPC host project. Application VMs in multiple service projects need a rule that allows TCP 8443 traffic only between VMs that share a common workload identity, regardless of their IP addresses, which change frequently due to autoscaling. The engineer wants the rule to remain valid even if VMs are recreated with new IPs, and to work across the VPC network. Which approach should the engineer use to define the source and target in the network firewall policy rule?

Reviewed for accuracy · Report an issueNext question