Professional Cloud Security EngineerConfiguring network securityMedium
A global e-commerce company uses Google Cloud for its web application. They need to ensure that their customers experience low latency and high availability regardless of their geographic location. Additionally, the company wants to protect its application from DDoS attacks and common web vulnerabilities. Which combination of Google Cloud networking services should they implement?
- ACloud Load Balancing (Global External HTTP(S) Load Balancer), Cloud CDN, and Cloud Armor
- BCloud Load Balancing (Global External HTTP(S) Load Balancer) and Cloud Armor
- CCloud Load Balancing (Global External HTTP(S) Load Balancer) and Cloud CDN
- DCloud Load Balancing (Internal HTTP(S) Load Balancer), Cloud CDN, and Cloud Armor
Show answer & explanationAnswer & explanation
Correct answer: A. Cloud Load Balancing (Global External HTTP(S) Load Balancer), Cloud CDN, and Cloud Armor
A Global External HTTP(S) Load Balancer distributes traffic globally for low latency and high availability. Cloud CDN caches content closer to users for faster delivery. Cloud Armor provides DDoS protection and WAF capabilities to secure the application.
Why the other options are wrong
- B. This option lacks the content caching and low-latency benefits of Cloud CDN for static content.
- C. This option lacks DDoS protection and WAF capabilities provided by Cloud Armor.
- D. An Internal HTTP(S) Load Balancer is for internal traffic within a VPC, not for external customer access and global distribution.
Global External HTTP(S) LB, CDN, & Cloud Armor
This combination provides a robust solution for globally distributed web applications, offering performance, availability, and security.
- Global External HTTP(S) Load Balancer for global traffic distribution and low latency.
- Cloud CDN for caching static content closer to users, improving performance.
- Cloud Armor for DDoS protection and Web Application Firewall (WAF) capabilities.
Memory trick: Global LB routes, CDN speeds, Armor protects.