🔥 3-day streak
Google Cloud Professional Cloud Network Engineer100 / 142
Question 100 of 142
Your security team manages VPC firewall rules for a large production environment. Currently, ingress rules use network tags to identify which VMs may receive traffic on port 8080. Developers with the Compute Instance Admin role can freely add and remove network tags on their own VMs, which the security team considers a compliance risk because it lets developers grant themselves access covered by firewall rules. The security team wants firewall targeting that developers cannot self-assign without a privileged IAM permission. What should you do?
Reviewed for accuracy · Report an issueNext question