Professional Cloud Security EngineerManaging operationsEasy
A healthcare provider is deploying a new web application that handles protected health information (PHI) on Google Cloud. Before launching, they need to perform an automated scan to identify common web vulnerabilities like SQL injection, cross-site scripting (XSS), and outdated libraries. The scan should be integrated into their CI/CD pipeline and provide actionable findings. Which Google Cloud service should they use?
- AWeb Security Scanner (WSS)
- BEvent Threat Detection (ETD)
- CContainer Threat Detection (CTD)
- DSecurity Health Analytics (SHA)
Show answer & explanationAnswer & explanation
Correct answer: A. Web Security Scanner (WSS)
Web Security Scanner (WSS) is specifically designed to scan public-facing web applications for common vulnerabilities like SQL injection and XSS, making it ideal for pre-launch security assessments and CI/CD integration.
Why the other options are wrong
- B. ETD detects suspicious activities from logs, not web application vulnerabilities.
- C. CTD monitors running containers for runtime threats, not web application vulnerabilities.
- D. SHA focuses on Google Cloud resource misconfigurations, not web application vulnerabilities.
Web Security Scanner (WSS)
A Google Cloud service that automatically scans public and private web applications for common vulnerabilities such as XSS, SQL injection, and mixed content issues.
- Automated DAST (Dynamic Application Security Testing).
- Detects common web vulnerabilities.
- Integrates with Security Command Center.
- Can be incorporated into CI/CD pipelines.
Memory trick: Web Security Scanner scans the web, so no bad code gets through the web.