Professional Cloud Security EngineerConfiguring network securityEasy

A company operates a web application that experiences frequent DDoS attacks. They need a solution that can protect their application, which is fronted by a global external HTTP(S) Load Balancer, from various web-based threats, including SQL injection, cross-site scripting (XSS), and Layer 7 DDoS attacks. Which Google Cloud service should be implemented to address these security concerns?

  1. ACloud VPN
  2. BCloud Armor
  3. CVPC Firewall Rules
  4. DVPC Service Controls
Show answer & explanation

Correct answer: B. Cloud Armor

Cloud Armor is a WAF (Web Application Firewall) and DDoS protection service that integrates with Google Cloud Load Balancing to protect web applications from various L3/L4 and L7 attacks, including SQL injection, XSS, and DDoS.

Why the other options are wrong

  • A. Cloud VPN creates secure connections between networks, not web application security.
  • C. VPC Firewall Rules operate at L3/L4 and do not provide WAF capabilities or advanced L7 DDoS protection.
  • D. VPC Service Controls prevent data exfiltration, not web application attacks.

Cloud Armor

Cloud Armor is a DDoS protection and WAF service that works with Google Cloud Load Balancing to protect applications from various web-based threats.

  • DDoS protection (L3/L4 and L7)
  • Web Application Firewall (WAF) capabilities
  • Integrates with HTTP(S) Load Balancers

Memory trick: Armor protects the web castle from all attacking armies.

More Configuring network security questions