nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #284

Customers complain about error messages when they access your organization's website. You suspect that the web application firewall rules configured in Cloud Armor are too strict. You want to…

The correct answer is B. Enable logging in the Application Load Balancer backend and set the log level to VERBOSE in. https://cloud.google.com/armor/docs/verbose-logging You can adjust the level of detail recorded in your logs. We recommend that you enable verbose logging only when you first create a policy, make changes to a policy, or troubleshoot a policy. If you enable verbose logging, it…

Submitted by mateo_ar· Apr 18, 2026Configuring network security

Question

Customers complain about error messages when they access your organization's website. You suspect that the web application firewall rules configured in Cloud Armor are too strict. You want to collect request logs to investigate what triggered the rules and blocked the traffic. What should you do?

Options

  • AModify the Application Load Balancer backend and increase the tog sample rate to a higher
  • BEnable logging in the Application Load Balancer backend and set the log level to VERBOSE in
  • CChange the configuration of suspicious web application firewall rules in the Cloud Armor policy to
  • DCreate a log sink with a filter for togs containing redirected_by_security_policy and set a

How the community answered

(27 responses)
  • A
    4% (1)
  • B
    81% (22)
  • C
    4% (1)
  • D
    11% (3)

Explanation

https://cloud.google.com/armor/docs/verbose-logging You can adjust the level of detail recorded in your logs. We recommend that you enable verbose logging only when you first create a policy, make changes to a policy, or troubleshoot a policy. If you enable verbose logging, it is in effect for rules in preview mode as well as active (non- previewed) rules during standard operations.

Topics

#Cloud Armor#Logging#Web Application Firewall (WAF)#Application Load Balancer

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice