Professional Cloud ArchitectDesign for security and complianceMedium
An online gaming company is experiencing frequent DDoS attacks targeting its public-facing game servers hosted on Google Compute Engine. These attacks lead to service unavailability and a poor user experience. The company needs a managed service that can protect its applications from various types of network and application layer DDoS attacks, as well as provide Web Application Firewall (WAF) capabilities to mitigate common web vulnerabilities. Which Google Cloud service should they implement?
- ACloud CDN
- BNetwork Firewall Rules
- CCloud Armor
- DVPC Service Controls
Show answer & explanationAnswer & explanation
Correct answer: C. Cloud Armor
Cloud Armor is a DDoS protection and Web Application Firewall (WAF) service that inspects incoming traffic to public-facing applications, protecting them from various L3/L4 and L7 DDoS attacks and common web vulnerabilities.
Why the other options are wrong
- A. Cloud CDN caches content to improve performance and availability but does not provide DDoS protection or WAF capabilities.
- B. Network Firewall Rules control traffic flow at the network level (IP/port) but are not designed for advanced DDoS mitigation or WAF functionality.
- D. VPC Service Controls protect against data exfiltration within an organization, not external DDoS attacks or web vulnerabilities.
Cloud Armor
A Google Cloud service that provides DDoS protection and Web Application Firewall (WAF) capabilities for applications deployed on Google Cloud.
- Protects against L3/L4 volumetric attacks and L7 application attacks.
- Integrates with HTTP(S) Load Balancing.
- Offers preconfigured WAF rules and custom rules for traffic filtering.
Memory trick: Armor for Apps, Shields from Storms.