PROFESSIONAL-CLOUD-NETWORK-ENGINEER · Question #223
You plan to deploy Google Cloud Armor web application firewall (WAF) policies that use the preconfigured WAF rules. You want all Google Cloud Armor logs to be sent to Cloud Logging with the highest…
The correct answer is C. Enable Google Cloud Armor logging for all the backend services where Cloud Armor WAF. Enable Google Cloud Armor logging: Logging must be explicitly enabled for each backend service where Cloud Armor WAF policies are applied. Without enabling this logging, detailed logs for Cloud Armor won't be generated. Set logging level to VERBOSE: The VERBOSE logging level…
Question
Options
- ASet the sample rate of the Cloud Load Balancing logs to 0.5.
- BSet the Google Cloud Armor logging option to VERBOSE.
- CEnable Google Cloud Armor logging for all the backend services where Cloud Armor WAF
- DSet the sample rate of the Cloud Load Balancing logs to 1.0.
How the community answered
(58 responses)- A7% (4)
- B3% (2)
- C79% (46)
- D10% (6)
Explanation
Enable Google Cloud Armor logging: Logging must be explicitly enabled for each backend service where Cloud Armor WAF policies are applied. Without enabling this logging, detailed logs for Cloud Armor won't be generated. Set logging level to VERBOSE: The VERBOSE logging level captures the most detailed information, including request headers and more granular data about rule matches and actions taken by the WAF policies. This level provides the highest level of visibility for troubleshooting While enabling Cloud Load Balancing logs is necessary for general traffic logs, setting the Google Cloud Armor logging to VERBOSE ensures that all relevant WAF-related details are captured and sent to Cloud Logging.
Topics
Community Discussion
No community discussion yet for this question.