Google Cloud Digital LeaderSecurity and operations with Google CloudEasy

A small startup is deploying its first application on Google Cloud. They need a simple, cost-effective way to protect their web application from common web-based attacks like SQL injection and cross-site scripting without requiring extensive security expertise. Which Google Cloud service should they use?

  1. AVPC Service Controls
  2. BCloud Armor
  3. CSecurity Command Center
  4. DCloud KMS
Show answer & explanation

Correct answer: B. Cloud Armor

Cloud Armor provides DDoS protection and WAF capabilities for web applications, effectively defending against common web-based attacks. It's managed, making it suitable for a startup with limited security expertise.

Why the other options are wrong

  • A. VPC Service Controls focuses on data exfiltration prevention and access control for Google Cloud services, not web application attack protection.
  • C. Security Command Center provides a centralized security management and risk platform, not direct web application protection.
  • D. Cloud KMS is a key management service used for encrypting data, not protecting web applications from network attacks.

Cloud Armor

Cloud Armor is a DDoS protection and Web Application Firewall (WAF) service that helps defend applications and websites from various network and application layer attacks.

  • Protects against DDoS attacks and common web vulnerabilities (e.g., SQL injection, XSS).
  • Integrates with Google Cloud Load Balancing.
  • Offers pre-configured WAF rules and custom rules.

Memory trick: Armor guards the web castle from attackers.

More Security and operations with Google Cloud questions