Professional Cloud ArchitectDesign for security and complianceEasy

A multinational enterprise is migrating its legacy applications to Google Cloud. The security team has mandated that all external internet-facing applications must be protected against common web vulnerabilities, including SQL injection, cross-site scripting (XSS), and DDoS attacks. They also need granular control over traffic based on IP addresses and geographic locations. Which Google Cloud service should be implemented to address these requirements?

  1. AGoogle Cloud Armor
  2. BIdentity-Aware Proxy (IAP)
  3. CVPC Service Controls
  4. DCloud DLP
Show answer & explanation

Correct answer: A. Google Cloud Armor

Google Cloud Armor is a WAF (Web Application Firewall) service that protects applications against common web vulnerabilities like SQL injection and XSS, and mitigates DDoS attacks. It also offers geo-based and IP-based access controls, directly addressing all the stated requirements.

Why the other options are wrong

  • B. IAP controls access to applications based on user identity, not web vulnerabilities, DDoS attacks, or IP/geo-location based traffic filtering.
  • C. VPC Service Controls protect against data exfiltration by creating security perimeters, but do not protect against web vulnerabilities or DDoS attacks.
  • D. Cloud DLP (Data Loss Prevention) identifies and protects sensitive data, but does not provide WAF, DDoS protection, or access control for web applications.

Google Cloud Armor

Google Cloud Armor is a DDoS protection and Web Application Firewall (WAF) service that helps protect applications and websites from various types of attacks.

  • Provides Layer 3/4 and Layer 7 DDoS protection.
  • Offers WAF rules to mitigate common web vulnerabilities.
  • Allows IP-based and geo-based access control policies.
  • Integrates with Google Cloud Load Balancing.

Memory trick: Armor guards the gates from digital threats.

More Design for security and compliance questions