nerdexam
Google

PROFESSIONAL-CLOUD-ARCHITECT · Question #322

Your team is redacting a new application that is about to go into production. During testing, it emerges that a developer code allows user input to be used to modify the application and execute…

The correct answer is B. Web Security Scanner. What you need is a service that examines your code and finds out if something is vulnerable or insecure. Web Security Scanner does exactly this: it performs managed and custom web vulnerability scanning. It performs scans for OWASP, CIS GCP Foundation, PCI-DSS (and more)…

Submitted by lucia.co· Mar 30, 2026Designing for security and compliance

Question

Your team is redacting a new application that is about to go into production. During testing, it emerges that a developer code allows user input to be used to modify the application and execute commands.This event has thrown everyone into despair and has generated the fear that there are other problems of this type in the system. Which of the following services may help you?

Options

  • ACloud Armor
  • BWeb Security Scanner
  • CSecurity Command Center
  • DShielded GKE nodes

How the community answered

(28 responses)
  • A
    7% (2)
  • B
    89% (25)
  • D
    4% (1)

Explanation

What you need is a service that examines your code and finds out if something is vulnerable or insecure. Web Security Scanner does exactly this: it performs managed and custom web vulnerability scanning. It performs scans for OWASP, CIS GCP Foundation, PCI-DSS (and more) published findings. A is wrong because Cloud Armor is a Network Security Service, with WAF rules, DDoS and application attacks defenses. C is wrong because the Security Command Center suite contains Web Security Scanner and many other services. D is wrong because Shielded GKE nodes are special and secured VMs.

Topics

#Web Security Scanner#OWASP vulnerabilities#injection attacks#application security

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-ARCHITECT Practice