Professional Cloud Security EngineerManaging operationsEasy

A healthcare provider is deploying a new web application that handles protected health information (PHI) on Google Cloud. Before launching, they need to perform an automated scan to identify common web vulnerabilities like SQL injection, cross-site scripting (XSS), and outdated libraries. The scan should be integrated into their CI/CD pipeline and provide actionable findings. Which Google Cloud service should they use?

  1. AWeb Security Scanner (WSS)
  2. BEvent Threat Detection (ETD)
  3. CContainer Threat Detection (CTD)
  4. DSecurity Health Analytics (SHA)
Show answer & explanation

Correct answer: A. Web Security Scanner (WSS)

Web Security Scanner (WSS) is specifically designed to scan public-facing web applications for common vulnerabilities like SQL injection and XSS, making it ideal for pre-launch security assessments and CI/CD integration.

Why the other options are wrong

  • B. ETD detects suspicious activities from logs, not web application vulnerabilities.
  • C. CTD monitors running containers for runtime threats, not web application vulnerabilities.
  • D. SHA focuses on Google Cloud resource misconfigurations, not web application vulnerabilities.

Web Security Scanner (WSS)

A Google Cloud service that automatically scans public and private web applications for common vulnerabilities such as XSS, SQL injection, and mixed content issues.

  • Automated DAST (Dynamic Application Security Testing).
  • Detects common web vulnerabilities.
  • Integrates with Security Command Center.
  • Can be incorporated into CI/CD pipelines.

Memory trick: Web Security Scanner scans the web, so no bad code gets through the web.

More Managing operations questions