Memory hook: Filter packets, protect apps, inspect egress.
Must remember
- VPC firewall rules are stateful and use direction, protocol, ports, targets and sources/destinations. Hierarchical and network firewall policies add organization-wide structure; understand policy evaluation and delegation before migration.
- Cloud NGFW Essentials/Standard/Enterprise expose different capabilities. Select threat intelligence or deeper inspection only when required; use supported secure tags/service-account targeting for segmentation rather than unmaintained IP lists.
- Cloud Armor protects supported load-balanced traffic with WAF rules, rate limits and other protections. Edge/backend policy placement matters; tune SQLi/XSS rules in preview before blocking legitimate traffic.
- Public Cloud NAT enables supported outbound connections for internal-only resources without accepting unsolicited inbound sessions. Monitor ports and address capacity; static versus dynamic port allocation affects scaling and exhaustion.
- Secure Web Proxy applies supported outbound web controls. It is distinct from Cloud NAT address translation and from an inbound WAF.
- Use supported multi-NIC appliances, policy-based routes or internal load-balancer next hops for inline inspection. Packet Mirroring copies traffic to collectors for out-of-band analysis; copies do not block the original flow.
Review details
Firewall selection depends on effective hierarchical, network and VPC policy evaluation, not simply the lowest number found anywhere. Within a rule model, direction, targets, matching source/destination, protocol and priority determine eligibility. Secure tags have an IAM-controlled governance model distinct from ordinary network tags; inventory labels are not automatically traffic selectors.
Cloud Armor rule preview helps assess WAF/rate/bot rules before enforcement. Supported Adaptive Protection and advanced DDoS capabilities depend on service/tier and traffic path. NAT port allocation or address exhaustion causes outbound failures even when firewall and route are valid; monitor dropped/error signals and per-VM port use.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Stop abusive HTTP requests | Cloud Armor policy on the supported load balancer, tuned to the traffic. |
| Inspect a copy without changing forwarding | Packet Mirroring with an appropriately sized collector. |
Traps
- Cloud NAT is not an inbound firewall-opening mechanism.
- An out-of-band collector cannot block packets merely by observing them.
Active recall
1. What is a NAT exhaustion symptom?
New outbound connections fail while existing traffic may continue; inspect port allocation and errors.
2. Why preview WAF rules?
To measure false positives before enforcing blocks.
3. What is the purpose of secure tags?
Governed identity-like resource grouping for supported firewall policy targeting.
4. Does a route permit traffic through a firewall?
No; routing and policy must both allow the path.
5. Why ensure symmetric appliance paths?
Stateful inspection can fail when request and response traverse different uncoordinated state.