
Ultimate access to all questions.
Your company has Compute Engine instances with public internet exposure, each having a single network interface with one public IP address. You need to prevent connection attempts from internet clients whose IP addresses belong to the BGP_ASN_TOBLOCK BGP ASN. What is the recommended solution?
A
Create a new Cloud Armor backend security policy, and use the --network-src-asns parameter.
B
Create a new Cloud Armor network edge security policy, and use the --network-src-asns parameter.
C
Create a new Cloud Armor edge security policy, and use the --network-src-asns parameter.
D
Create a new firewall policy ingress rule, and use the --network-src-asns parameter.