Professional Cloud Security EngineerConfiguring network securityMedium

A security auditor needs to ensure that a web application hosted on Google Cloud is protected against common web vulnerabilities, such as SQL injection and cross-site scripting (XSS), and also against volumetric DDoS attacks. The application is served via a Global External HTTP(S) Load Balancer. Which Google Cloud service should be configured to provide this comprehensive protection?

  1. AVPC Service Controls
  2. BCloud Armor
  3. CCloud DNS
  4. DCloud VPN
Show answer & explanation

Correct answer: B. Cloud Armor

Cloud Armor is Google Cloud's DDoS protection and Web Application Firewall (WAF) service. It integrates with Global External HTTP(S) Load Balancers to protect against both volumetric DDoS attacks and common web vulnerabilities like SQL injection and XSS.

Why the other options are wrong

  • A. VPC Service Controls help prevent data exfiltration, not protect against web application attacks or DDoS.
  • C. Cloud DNS provides domain name resolution, not security protection for web applications.
  • D. Cloud VPN creates secure tunnels between networks, unrelated to web application security or DDoS protection.

Cloud Armor

A Google Cloud security service providing DDoS protection and Web Application Firewall (WAF) capabilities.

  • Protects against L3/L4 and L7 DDoS attacks
  • Offers preconfigured WAF rules against common web vulnerabilities (OWASP Top 10)
  • Integrates with Global External HTTP(S) Load Balancers

Memory trick: Armor your web apps from all attacks.

More Configuring network security questions