Professional Cloud Security EngineerManaging operationsMedium

A company is developing a new serverless application using Cloud Functions and wants to ensure that all HTTP requests to these functions are continuously monitored for potential web-based vulnerabilities such as cross-site scripting (XSS) and SQL injection. They need an automated solution that provides findings directly in Security Command Center. Which Google Cloud service should they use?

  1. AEvent Threat Detection
  2. BCloud Armor with WAF policies
  3. CWeb Security Scanner
  4. DSecurity Health Analytics
Show answer & explanation

Correct answer: C. Web Security Scanner

Web Security Scanner is designed to scan deployed web applications, including serverless functions exposed via HTTP, for common web vulnerabilities like XSS, SQL injection, and mixed content. It generates findings directly in Security Command Center.

Why the other options are wrong

  • A. Event Threat Detection analyzes logs for behavioral threats, not for scanning application code for web vulnerabilities.
  • B. Cloud Armor is a WAF that *prevents* attacks but doesn't *scan* for vulnerabilities in the application code or configuration. It's a different security control.
  • D. Security Health Analytics checks for misconfigurations in Google Cloud resources, not for web application-level vulnerabilities like XSS or SQL injection.

Web Security Scanner

A Google Cloud service that scans deployed web applications for common web vulnerabilities such as XSS, SQL injection, and insecure headers, and reports findings to Security Command Center.

  • Actively crawls and analyzes web applications.
  • Detects common web vulnerabilities (XSS, SQLi, etc.).
  • Reports findings to Security Command Center.
  • Can be scheduled for continuous scanning.

Memory trick: Web Security Scanner is like a 'web spider' looking for 'security holes' in your application.

More Managing operations questions