Google Cloud Digital LeaderSecurity and operations with Google CloudHard

A media streaming service uses Google Cloud to deliver content globally. They are experiencing frequent Distributed Denial of Service (DDoS) attacks targeting their public-facing web applications and APIs, causing service disruptions. They need a managed service that can protect their applications from L3/L4 and L7 DDoS attacks and provide Web Application Firewall (WAF) capabilities. Which Google Cloud security product should they implement?

  1. ACloud Load Balancing
  2. BCloud Armor
  3. CVPC Firewall
  4. DCloud CDN
Show answer & explanation

Correct answer: B. Cloud Armor

Cloud Armor is a DDoS protection and Web Application Firewall (WAF) service. It protects applications and websites from various network and application layer attacks, including L3/L4 (volume-based) and L7 (application-layer) DDoS attacks, by filtering malicious traffic at the edge of Google's network.

Why the other options are wrong

  • A. Cloud Load Balancing distributes traffic across instances, offering some basic protection by absorbing traffic, but lacks advanced DDoS and WAF features.
  • C. VPC Firewall controls traffic to/from VMs within a VPC, but it's not designed for public-facing DDoS protection or WAF.
  • D. Cloud CDN (Content Delivery Network) caches content closer to users, improving performance, but does not provide DDoS or WAF capabilities.

Cloud Armor

Cloud Armor is a DDoS protection and Web Application Firewall (WAF) service that helps protect your Google Cloud applications and websites from various types of attacks.

  • Protects against L3/L4 volumetric DDoS attacks.
  • Provides WAF capabilities for L7 application-layer attacks.
  • Integrates with Google Cloud Load Balancing for edge protection.

Memory trick: Armor Shields Apps from DDoS and WAF.

More Security and operations with Google Cloud questions