Professional Cloud Security EngineerManaging operationsEasy
A company is implementing a new application that processes sensitive customer data. They need to ensure that any potential SQL injection vulnerabilities are identified before the application is deployed to production. Which Google Cloud service should be used to scan the web application for such vulnerabilities?
- AContainer Threat Detection
- BWeb Security Scanner
- CSecurity Health Analytics
- DEvent Threat Detection
Show answer & explanationAnswer & explanation
Correct answer: B. Web Security Scanner
Web Security Scanner is designed to scan deployed or running web applications for common vulnerabilities like SQL injection, cross-site scripting (XSS), and outdated libraries. It's the most appropriate tool for identifying such issues before production deployment.
Why the other options are wrong
- A. Container Threat Detection focuses on runtime threats in containerized environments, not web application vulnerabilities.
- C. Security Health Analytics assesses security misconfigurations and compliance issues, not active web application vulnerabilities.
- D. Event Threat Detection identifies threats from Cloud Logging data, not by scanning web applications directly.
Web Security Scanner
Web Security Scanner is an automated vulnerability scanner for web applications hosted on Google Cloud. It identifies common vulnerabilities like cross-site scripting (XSS), SQL injection, mixed content, and outdated libraries.
- Scans deployed or running web applications.
- Detects common web vulnerabilities.
- Integrated with Security Command Center.
Memory trick: Web app detective finds hidden flaws.