Google Cloud Digital LeaderSecurity and operations with Google CloudEasy
A small startup is deploying its first application on Google Cloud. They need a simple, cost-effective way to protect their web application from common web exploits like SQL injection and cross-site scripting (XSS) without extensive configuration. Which Google Cloud security product should they use?
- ACloud CDN
- BCloud Load Balancing (with Google Cloud Armor)
- CSecret Manager
- DCloud IDS
Show answer & explanationAnswer & explanation
Correct answer: B. Cloud Load Balancing (with Google Cloud Armor)
Cloud Load Balancing, when integrated with Google Cloud Armor, provides WAF capabilities to protect against common web attacks. It's a foundational service for web applications.
Why the other options are wrong
- A. Cloud CDN caches content for performance, it does not provide security against web exploits.
- C. Secret Manager is for securely storing API keys, passwords, and certificates, not for protecting web applications from exploits.
- D. Cloud IDS is for detecting network-based threats, not specifically web application exploits.
Cloud Load Balancing with Cloud Armor
Google Cloud Load Balancing distributes incoming traffic across multiple instances, and when combined with Cloud Armor, it provides robust DDoS protection and Web Application Firewall (WAF) capabilities.
- Distributes traffic efficiently.
- Protects against DDoS attacks.
- WAF defends against common web exploits like SQLi and XSS.
- Scalable and integrated with other Google Cloud services.
Memory trick: Load Balancer Armor for web app shore.