GCP PCA · Question 37 · Network Topologies
You are the network administrator for a large GCP organization. The security team wants to enforce a rule that blocks all outbound SSH traffic to the internet across ALL projects in the organization. Individual project owners must not be able to override this rule. Which TWO steps should you take? (Select TWO)
Answer options:
Create a standard VPC firewall rule in every project with a priority of 0.
Create a Hierarchical Firewall Policy at the Organization node.
Configure an Organization Policy constraint to disable SSH.
Use VPC Service Controls to block port 22.
Add a rule to the policy to deny egress traffic on port 22 and set the action to 'Deny'.
50 questions · hints · full answers · grading