Professional Cloud Security EngineerConfiguring network securityHard

A company is deploying a critical internal application in Google Cloud that needs to be accessible only by specific internal IP addresses within their VPC network. The application must not have any external IP addresses, and its traffic should never leave the Google Cloud network. They need to distribute incoming requests across multiple backend instances for high availability and scalability. Which type of Google Cloud Load Balancer should they choose?

  1. AGlobal External HTTP(S) Load Balancer
  2. BExternal TCP Proxy Load Balancer
  3. CInternal TCP/UDP Load Balancer
  4. DInternal HTTP(S) Load Balancer
Show answer & explanation

Correct answer: D. Internal HTTP(S) Load Balancer

An Internal HTTP(S) Load Balancer is designed for internal applications, using only internal IP addresses within a VPC network. It provides HTTP/S layer 7 load balancing, which is suitable for distributing requests to backend instances while ensuring traffic never leaves the Google Cloud private network.

Why the other options are wrong

  • A. Global External HTTP(S) Load Balancer uses external IP addresses and is for public-facing applications, which contradicts the requirement for internal-only access.
  • B. External TCP Proxy Load Balancer uses external IP addresses and is for public-facing TCP traffic, not internal-only HTTP/S applications.
  • C. Internal TCP/UDP Load Balancer operates at Layer 4 (TCP/UDP) and is suitable for non-HTTP/S internal applications. The problem specifies an 'application' which usually implies HTTP/S for web, making Internal HTTP(S) more appropriate for layer 7 features.

Internal HTTP(S) Load Balancer

A Google Cloud Load Balancer that distributes HTTP/S traffic to backend instances using only internal IP addresses.

  • Operates at Layer 7 (HTTP/S)
  • Uses internal IP addresses, keeping traffic private within the VPC
  • Provides high availability and scalability for internal applications

Memory trick: Balance your internal apps, privately and perfectly.

More Configuring network security questions