Using Google‑recommended practices, you must allow only VM A to initiate traffic to VM B inside a VPC and block all other flows. No other firewall rules exist. Which firewall rule enforces this?
Choose an answer
Tap an option to check your answer.
Correct answer: Direction: ingress, Action: allow — Target: VM B service account — Source: VM A service account — Priority: 1000.
Why this is the answer
The correct rule allows ingress traffic to VM B (the target) only when it originates from VM A (the source). Using service accounts for both the target and source is a recommended practice for granular control and dynamic membership. The default priority of 1000 is standard. The second option is incorrect because using a VM A tag and VM A source IP for the source is redundant and less flexible than a service account. The third and fourth options are incorrect because they reverse the target and source, attempting to allow traffic from VM A to VM B, which is not what the question asks. The question specifies VM A initiates traffic to VM B, meaning VM B is the destination (target) and VM A is the origin (source).
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed