Google Cloud Digital LeaderSecurity and operations with Google CloudHard
A media streaming service uses Google Cloud to deliver content globally. They are experiencing frequent Distributed Denial of Service (DDoS) attacks targeting their public-facing web applications and APIs, causing service disruptions. They need a managed service that can protect their applications from L3/L4 and L7 DDoS attacks and provide Web Application Firewall (WAF) capabilities. Which Google Cloud security product should they implement?
- ACloud Load Balancing
- BCloud Armor
- CVPC Firewall
- DCloud CDN
Show answer & explanationAnswer & explanation
Correct answer: B. Cloud Armor
Cloud Armor is a DDoS protection and Web Application Firewall (WAF) service. It protects applications and websites from various network and application layer attacks, including L3/L4 (volume-based) and L7 (application-layer) DDoS attacks, by filtering malicious traffic at the edge of Google's network.
Why the other options are wrong
- A. Cloud Load Balancing distributes traffic across instances, offering some basic protection by absorbing traffic, but lacks advanced DDoS and WAF features.
- C. VPC Firewall controls traffic to/from VMs within a VPC, but it's not designed for public-facing DDoS protection or WAF.
- D. Cloud CDN (Content Delivery Network) caches content closer to users, improving performance, but does not provide DDoS or WAF capabilities.
Cloud Armor
Cloud Armor is a DDoS protection and Web Application Firewall (WAF) service that helps protect your Google Cloud applications and websites from various types of attacks.
- Protects against L3/L4 volumetric DDoS attacks.
- Provides WAF capabilities for L7 application-layer attacks.
- Integrates with Google Cloud Load Balancing for edge protection.
Memory trick: Armor Shields Apps from DDoS and WAF.