🔥 3-day streak
Google Cloud Professional Cloud Network Engineer99 / 142
Question 99 of 142

A security engineer is building a global network firewall policy for a VPC. They create a rule at priority 1000 that allows TCP 443 ingress to instances whose target is the service account 'web-sa@project.iam.gserviceaccount.com'. Separately, another engineer creates a rule at priority 900 that denies all ingress to instances with the secure tag 'quarantine'. An instance is running with the service account 'web-sa' AND has the secure tag 'quarantine' applied. Incoming HTTPS traffic to this instance is being dropped. What is the correct explanation?

Reviewed for accuracy · Report an issueNext question