6Configuring, implementing, and managing a cloud network security solution
- 6.1Cloud Armor and Cloud NGFW / VPC firewall
Understand Google Cloud Armor policies (edge/backend security policies, WAF (SQLi/XSS/RFI), advanced network DDoS and Adaptive Protection, rate limiting, bot management, Threat Intelligence) and Cloud NGFW/VPC firewall rules (firewall strategy, hierarchical firewall, effective policy, L7 inspection (NGFW Enterprise), migration from VPC rules, rule criteria (priority/protocol/direction/source/destination), firewall logging, micro-segmentation, NGFW tiers (Essentials/Standard/Enterprise)).
- 6.2Cloud NAT, Secure Web Proxy, and NVA / Packet Mirroring
Understand public Cloud NAT IP addressing (automatic/manual allocation) and static/dynamic port allocation, controlling egress with Secure Web Proxy, self-managed network virtual appliances (multi-NIC VMs/NGFW appliances) with an internal LB as next hop for HA routing, policy-based routes for HA multi-NIC VMs, out-of-band Network Security Integration, and Packet Mirroring to self-managed collectors.

