You must centrally manage firewall rules across dozens of projects so security teams can push global blocking rules without modifying each project. Which Google Cloud feature is designed for that centralized enforcement?
Choose an answer
Tap an option to check your answer.
Correct answer: Hierarchical Network Firewall Policies applied at the organization or folder level.
Why this is the answer
Hierarchical Network Firewall Policies allow you to define and enforce firewall rules at the organization or folder level, which then apply to all projects and VPC networks within that hierarchy. This provides centralized management and enforcement, ensuring consistent security policies across dozens of projects without individual modifications. Creating identical per-project compute.firewalls via a deployment pipeline is a manual or scripted approach that lacks true centralized enforcement and scalability. Cloud Armor WAF policies are for protecting external-facing applications from web-based attacks, not for internal network firewalling between VMs. VPC peering with a hub project can centralize network connectivity, but firewall rules are still typically applied at the individual VPC level, not globally enforced from the hub in this manner.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed