nerdexam
GoogleGoogle

PROFESSIONAL-CLOUD-ARCHITECT · Question #298

PROFESSIONAL-CLOUD-ARCHITECT Question #298: Real Exam Question with Answer & Explanation

Sign in or unlock PROFESSIONAL-CLOUD-ARCHITECT to reveal the answer and full explanation for question #298. The question stem and answer options stay visible for context.

Submitted by akirajp· Mar 30, 2026

Question

You are designing the network architecture for a public-facing, containerized web application deployed on Cloud Run. All incoming traffic must be inspected by a Cloud Armor web application firewall (WAF) before reaching the application. You plan to use an Application Load Balancer, which will have the Cloud Armor policy attached. You must ensure that all public requests pass through the load balancer and any attempt to access the Cloud Run service directly through its default *.run.app URL is blocked. What should you do?

Options

  • AEnable Identity-Aware Proxy (IAP) directly on the Cloud Run service to intercept and validate all
  • BCreate a DNS entry to route traffic to Cloud Armor. Configure Cloud Armor to deny traffic from
  • CSet the Cloud Run ingress to Allow internal traffic and Cloud Load Balancing, and use a
  • DConfigure a VPC firewall rule with a high priority to deny all traffic that does not originate from the

Unlock PROFESSIONAL-CLOUD-ARCHITECT to see the answer

You've previewed enough free PROFESSIONAL-CLOUD-ARCHITECT questions. Unlock PROFESSIONAL-CLOUD-ARCHITECT for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full PROFESSIONAL-CLOUD-ARCHITECT PracticeBrowse All PROFESSIONAL-CLOUD-ARCHITECT Questions