nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #14

An engineering team is launching a web application that will be public on the internet. The web application is hosted in multiple GCP regions and will be directed to the respective backend based on…

The correct answer is A. Cloud Armor. The Cloud armor able to directed user traffic to an external HTTP(S) load balancer enters the PoP closest to the user in Premium Tier. https://cloud.google.com/armor/docs/security-policy-overview#edge-security

Submitted by noor.lb· Apr 18, 2026Configuring network security

Question

An engineering team is launching a web application that will be public on the internet. The web application is hosted in multiple GCP regions and will be directed to the respective backend based on the URL request. Your team wants to avoid exposing the application directly on the internet and wants to deny traffic from a specific list of malicious IP addresses Which solution should your team implement to meet these requirements?

Options

  • ACloud Armor
  • BNetwork Load Balancing
  • CSSL Proxy Load Balancing
  • DNAT Gateway

How the community answered

(44 responses)
  • A
    82% (36)
  • B
    2% (1)
  • C
    11% (5)
  • D
    5% (2)

Explanation

The Cloud armor able to directed user traffic to an external HTTP(S) load balancer enters the PoP closest to the user in Premium Tier. https://cloud.google.com/armor/docs/security-policy-overview#edge-security

Topics

#Network Security#Web Application Firewall#DDoS Protection#IP Filtering

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice