A Network Intelligence Center connectivity test shows packets are dropped by a VPC firewall rule but does not show which rule name matched. You need the exact rule name and counts of matches. Which action provides that information?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable VPC firewall rule logging for the project and inspect the firewall rule log entries in Cloud Logging..
Why this is the answer
Enabling VPC firewall rule logging is the direct and intended method to get detailed information about firewall rule matches, including the rule name and hit counts. These logs are sent to Cloud Logging, where you can query them to identify the specific rule that dropped the packets. Packet mirroring captures full packet data but doesn't inherently provide the firewall rule name that caused a drop. Manually changing firewall rule priorities is an operational change, not a logging mechanism, and won't provide the requested information. While VPC Flow Logs record network flows, they do not include the specific firewall rule name that was matched or denied the traffic.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed