Restrict inter-VM traffic in an autoscaling VPC without relying on static IPs or fixed subnets. How should you enforce allowed paths and ports?
Choose an answer
Tap an option to check your answer.
Correct answer: Use firewall rules based on network tags attached to the compute instances.
Why this is the answer
Network tags are ideal for dynamic environments like autoscaling groups because they are assigned to instances, not IP addresses or subnets. You can create firewall rules that allow or deny traffic based on these tags, ensuring that as instances scale up or down, the correct network policies are automatically applied. This enforces allowed paths and ports without needing static configurations. Separate VPCs create isolated networks, which is too restrictive for inter-VM traffic within a single application. Cloud DNS resolves hostnames to IPs but doesn't enforce network access. Service accounts control API access and resource permissions, not network traffic flow between VMs.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed