An organization-level hierarchical firewall policy explicitly denies ICMP to a set of projects, while a project-level VPC firewall rule allows ICMP to instances in one of those projects. Which statement is correct about ICMP traffic to those instances?
Choose an answer
Tap an option to check your answer.
Correct answer: The hierarchical policy denial takes precedence and ICMP will be denied.
Why this is the answer
Hierarchical firewall policies are evaluated before VPC firewall rules. When a hierarchical firewall policy explicitly denies traffic, that denial takes precedence over any VPC firewall rules, even if those rules would otherwise allow the traffic. This ensures that organization-level security controls are enforced consistently across all projects. Therefore, the hierarchical policy's denial of ICMP will override the project-level allow rule, and ICMP traffic will be denied. The project-level allow rule being "more specific" does not grant it precedence over a hierarchical deny. Policy replication windows are not relevant to policy enforcement order. Policy merging does not occur in a way that creates undefined behavior; the hierarchy dictates the order of evaluation.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed