Integrate an IDS appliance in us-west2 to inspect all VM egress payloads.
Choose an answer
Tap an option to check your answer.
Correct answer: Create an internal TCP/UDP load balancer as the packet mirroring collector and add a packet mirroring policy filtering egress traffic..
Why this is the answer
Packet Mirroring is the Google Cloud feature designed for sending copies of network traffic to an inspection appliance, like an IDS. To implement this, you configure a Packet Mirroring policy that specifies the source (VMs in us-west2) and the destination. The destination for mirrored packets is a collector, which must be an internal TCP/UDP load balancer. This load balancer then distributes the mirrored traffic to backend instances (your IDS appliances). Incorrect options: Firewall logging and VPC Flow Logs provide metadata about connections, not the actual packet payloads needed for deep inspection by an IDS. An internal HTTP(S) load balancer is designed for HTTP/HTTPS traffic and cannot act as a collector for raw mirrored packets.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed