Valid Professional-Cloud-Security-Engineer Dumps shared by ExamDiscuss.com for Helping Passing Professional-Cloud-Security-Engineer Exam! ExamDiscuss.com now offer the newest Professional-Cloud-Security-Engineer exam dumps, the ExamDiscuss.com Professional-Cloud-Security-Engineer exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com Professional-Cloud-Security-Engineer dumps with Test Engine here:
Your team creates an ingress firewall rule to allow SSH access from their corporate IP range to a specific bastion host on Compute Engine. Your team wants to make sure that this firewall rule cannot be used by unauthorized engineers who may otherwise have access to manage VMs in the development environment. What should your team do to meet this requirement?
Correct Answer: B
A is not correct because the network tag value can be inferred by examining the Firewall Rule or VM metadata. B is correct because access to the Service Account is required to use a firewall rule with a target of a Service Account. C is not correct because the target network tag value can be inferred by examining the Firewall Rule or VM metadata. D is not correct because the target subnet value can be inferred by examining the Firewall Rule or VM metadata. https://cloud.google.com/vpc/docs/firewalls#service-accounts-vs-tags