Professional Cloud Security EngineerEnsuring complianceMedium
An e-commerce company is experiencing a surge in traffic to its online store, leading to concerns about potential distributed denial-of-service (DDoS) attacks. They need to protect their public-facing web applications and APIs hosted on Google Cloud from various network and application layer attacks, including SQL injection and cross-site scripting (XSS), while also ensuring high availability and performance. Which Google Cloud service should they implement to achieve this comprehensive protection?
- ACloud Armor
- BNetwork Policy
- CCloud NAT
- DVPC Service Controls
Show answer & explanationAnswer & explanation
Correct answer: A. Cloud Armor
Cloud Armor is a DDoS protection and WAF (Web Application Firewall) service that helps protect public-facing applications from various attacks, including network DDoS, application-layer attacks like SQL injection and XSS. It integrates with Google Cloud Load Balancing to provide robust security.
Why the other options are wrong
- B. Network Policy in GKE controls traffic between pods but does not provide external DDoS or WAF protection for public-facing services.
- C. Cloud NAT allows instances without external IP addresses to send outbound traffic to the internet but does not provide security protection against attacks.
- D. VPC Service Controls creates security perimeters around resources to prevent data exfiltration but does not protect against external network/application attacks.
Cloud Armor
A Google Cloud service that provides DDoS protection and Web Application Firewall (WAF) capabilities to safeguard public-facing applications and APIs from various network and application layer attacks.
- Protects against DDoS attacks (L3/L4 and L7).
- Offers WAF rules for common web vulnerabilities (e.g., SQLi, XSS).
- Integrates with Google Cloud Load Balancing.
Memory trick: Cloud Armor: Your Web's Bouncer.