Google Cloud Digital LeaderSecurity and operations with Google CloudMedium

A media company uses Google Cloud for its content delivery platform. They need to protect their API endpoints from malicious traffic, including DDoS attacks and application-layer exploits. They also require custom rules based on geographic location and IP reputation. Which Google Cloud service should they use?

  1. ACloud Firewall
  2. BCloud DNS
  3. CGoogle Cloud Armor
  4. DCloud VPN
Show answer & explanation

Correct answer: C. Google Cloud Armor

Google Cloud Armor provides DDoS protection and a Web Application Firewall (WAF) for internet-facing applications, allowing custom rules based on various attributes including geographic location and IP reputation.

Why the other options are wrong

  • A. Cloud Firewall controls network traffic at a lower level (VMs), not specifically designed for API endpoint protection with WAF features.
  • B. Cloud DNS manages domain names and routes traffic, but does not provide security against DDoS or application exploits.
  • D. Cloud VPN establishes secure network tunnels, not for protecting public API endpoints from malicious traffic.

Google Cloud Armor

Google Cloud Armor is a DDoS and WAF service that protects internet-facing applications and services from various types of attacks, offering custom rules and preconfigured policies.

  • Protects against L3/L4 and L7 DDoS attacks.
  • Provides WAF capabilities against common web exploits.
  • Allows custom rules based on IP addresses, geographic regions, headers, and more.
  • Integrates with Cloud Load Balancing.

Memory trick: Armor shields the API's gate.

More Security and operations with Google Cloud questions