Google Cloud Digital LeaderSecurity and operations with Google CloudMedium
A media company uses Google Cloud for its content delivery platform. They need to protect their API endpoints from malicious traffic, including DDoS attacks and application-layer exploits. They also require custom rules based on geographic location and IP reputation. Which Google Cloud service should they use?
- ACloud Firewall
- BCloud DNS
- CGoogle Cloud Armor
- DCloud VPN
Show answer & explanationAnswer & explanation
Correct answer: C. Google Cloud Armor
Google Cloud Armor provides DDoS protection and a Web Application Firewall (WAF) for internet-facing applications, allowing custom rules based on various attributes including geographic location and IP reputation.
Why the other options are wrong
- A. Cloud Firewall controls network traffic at a lower level (VMs), not specifically designed for API endpoint protection with WAF features.
- B. Cloud DNS manages domain names and routes traffic, but does not provide security against DDoS or application exploits.
- D. Cloud VPN establishes secure network tunnels, not for protecting public API endpoints from malicious traffic.
Google Cloud Armor
Google Cloud Armor is a DDoS and WAF service that protects internet-facing applications and services from various types of attacks, offering custom rules and preconfigured policies.
- Protects against L3/L4 and L7 DDoS attacks.
- Provides WAF capabilities against common web exploits.
- Allows custom rules based on IP addresses, geographic regions, headers, and more.
- Integrates with Cloud Load Balancing.
Memory trick: Armor shields the API's gate.