Professional Cloud Security EngineerEnsuring complianceMedium

An e-commerce company is experiencing a surge in traffic to its online store, leading to concerns about potential distributed denial-of-service (DDoS) attacks. They need to protect their public-facing web applications and APIs hosted on Google Cloud from various network and application layer attacks, including SQL injection and cross-site scripting (XSS), while also ensuring high availability and performance. Which Google Cloud service should they implement to achieve this comprehensive protection?

  1. ACloud Armor
  2. BNetwork Policy
  3. CCloud NAT
  4. DVPC Service Controls
Show answer & explanation

Correct answer: A. Cloud Armor

Cloud Armor is a DDoS protection and WAF (Web Application Firewall) service that helps protect public-facing applications from various attacks, including network DDoS, application-layer attacks like SQL injection and XSS. It integrates with Google Cloud Load Balancing to provide robust security.

Why the other options are wrong

  • B. Network Policy in GKE controls traffic between pods but does not provide external DDoS or WAF protection for public-facing services.
  • C. Cloud NAT allows instances without external IP addresses to send outbound traffic to the internet but does not provide security protection against attacks.
  • D. VPC Service Controls creates security perimeters around resources to prevent data exfiltration but does not protect against external network/application attacks.

Cloud Armor

A Google Cloud service that provides DDoS protection and Web Application Firewall (WAF) capabilities to safeguard public-facing applications and APIs from various network and application layer attacks.

  • Protects against DDoS attacks (L3/L4 and L7).
  • Offers WAF rules for common web vulnerabilities (e.g., SQLi, XSS).
  • Integrates with Google Cloud Load Balancing.

Memory trick: Cloud Armor: Your Web's Bouncer.

More Ensuring compliance questions