Professional Cloud Security EngineerConfiguring network securityEasy
A company operates a web application that experiences frequent DDoS attacks. They need a solution that can protect their application, which is fronted by a global external HTTP(S) Load Balancer, from various web-based threats, including SQL injection, cross-site scripting (XSS), and Layer 7 DDoS attacks. Which Google Cloud service should be implemented to address these security concerns?
- ACloud VPN
- BCloud Armor
- CVPC Firewall Rules
- DVPC Service Controls
Show answer & explanationAnswer & explanation
Correct answer: B. Cloud Armor
Cloud Armor is a WAF (Web Application Firewall) and DDoS protection service that integrates with Google Cloud Load Balancing to protect web applications from various L3/L4 and L7 attacks, including SQL injection, XSS, and DDoS.
Why the other options are wrong
- A. Cloud VPN creates secure connections between networks, not web application security.
- C. VPC Firewall Rules operate at L3/L4 and do not provide WAF capabilities or advanced L7 DDoS protection.
- D. VPC Service Controls prevent data exfiltration, not web application attacks.
Cloud Armor
Cloud Armor is a DDoS protection and WAF service that works with Google Cloud Load Balancing to protect applications from various web-based threats.
- DDoS protection (L3/L4 and L7)
- Web Application Firewall (WAF) capabilities
- Integrates with HTTP(S) Load Balancers
Memory trick: Armor protects the web castle from all attacking armies.