Professional Cloud Security EngineerConfiguring network securityMedium

A security engineer is configuring a Global External HTTP(S) Load Balancer for a new web application. They need to ensure that the load balancer only accepts traffic from specific trusted IP ranges and blocks all other traffic at the edge of Google's network. Additionally, they want to implement rate-limiting to protect against potential abuse. Which Google Cloud service should be integrated with the load balancer to achieve these requirements?

  1. ACloud DNS
  2. BCloud Armor
  3. CVPC Service Controls
  4. DCloud CDN
Show answer & explanation

Correct answer: B. Cloud Armor

Cloud Armor is a WAF (Web Application Firewall) and DDoS protection service that integrates with Global External HTTP(S) Load Balancers. It allows you to configure security policies, including IP allow/deny lists and rate-limiting rules, at the edge of Google's network.

Why the other options are wrong

  • A. Cloud DNS provides domain name resolution but has no capabilities for traffic filtering or rate-limiting at the application layer.
  • C. VPC Service Controls prevents data exfiltration and unauthorized access to services but does not filter incoming HTTP(S) traffic at the load balancer edge.
  • D. Cloud CDN is for content caching and delivery optimization, not for traffic filtering or rate-limiting.

Cloud Armor

Cloud Armor is a web application firewall (WAF) and DDoS protection service that helps protect web applications and services from various internet-borne threats.

  • Integrates with Global External HTTP(S) Load Balancers.
  • Provides WAF rules, IP allow/deny lists, and rate-limiting.
  • Operates at the edge of Google's network for pre-emptive protection.

Memory trick: Cloud Armor is the bouncer for your load balancer.

More Configuring network security questions