Web servers run in prod-servers project in us-east1 and us-west1. The security team will install an IDS in its own project to inspect incoming traffic. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a new project and VPC for the security team, peer that VPC to the web servers’ VPC, deploy an internal load balancer and the IDS in both us-east1 and us-west1, enable Packet Mirroring, and create packet mirroring policies in the security project..
Why this is the answer
The correct option leverages Packet Mirroring, a Google Cloud feature designed for exactly this scenario. It allows you to forward copies of network traffic from specified VM instances to an IDS for analysis without altering the original traffic flow or requiring agents on the web servers. Deploying the IDS and an internal load balancer in both regions ensures high availability and regional traffic inspection. VPC peering connects the web server VPC to the security VPC, enabling communication for mirrored traffic. The other options are less suitable: Enabling IP forwarding on web servers or manually forwarding packets to the IDS is complex, error-prone, and not scalable. Using Shared VPC with IP forwarding or forwarding to a single-region IDS is inefficient and doesn't fully utilize Google Cloud's native traffic inspection capabilities across regions.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed