PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #36
A customer needs to launch a 3-tier internal web application on Google Cloud Platform (GCP). The customer's internal compliance requirements dictate that end-user access may only be allowed if the…
The correct answer is A. Cloud Armor. Cloud Armor (A) is GCP's managed web application firewall and DDoS protection service. It natively provides SYN flood mitigation at Google's network edge and supports IP/CIDR-based allow/deny security policies - directly satisfying both requirements. VPC Firewall Rules (B) can…
Question
Options
- ACloud Armor
- BVPC Firewall Rules
- CCloud Identity and Access Management
- DCloud CDN
How the community answered
(52 responses)- A75% (39)
- B6% (3)
- C15% (8)
- D4% (2)
Explanation
Cloud Armor (A) is GCP's managed web application firewall and DDoS protection service. It natively provides SYN flood mitigation at Google's network edge and supports IP/CIDR-based allow/deny security policies - directly satisfying both requirements. VPC Firewall Rules (B) can filter by source IP/CIDR but do not provide any DDoS or SYN flood protection. Cloud IAM (C) manages identity-based access to GCP APIs, not network-level traffic filtering. Cloud CDN (D) is a content delivery and caching service, not a security filtering product. Cloud Armor is the only product that combines CIDR-based access control with native SYN flood protection.
Topics
Community Discussion
No community discussion yet for this question.