GCP Professional Cloud Architect Practice Question
Your company runs a customer-facing ecommerce application on regional GKE clusters in us-central1 and europe-west1. Traffic is served through a global external HTTP(S) load balancer with Cloud CDN enabled. The security team requires (1) automatic mitigation of large-scale DDoS and OWASP Top 10 attacks at the edge and (2) detection of command-and-control or malware traffic inside the VPC without installing host agents. Which solution meets both requirements with minimal ongoing operations?
Replace the HTTP(S) load balancer with a TCP Proxy Load Balancer that has Google-managed protection enabled and rely on GKE network policies for internal threat detection.
Create a bastion host secured by OS Login, add rate-limiting VPC firewall rules on the load balancer, and use Packet Mirroring to send traffic to a self-managed Suricata IDS cluster.
Attach a Cloud Armor policy with adaptive DDoS protection and WAF rules to the HTTP(S) load balancer and create Cloud IDS endpoints in each regional subnet to monitor VPC traffic.
Use Cloud CDN signed URLs to absorb DDoS attacks and analyze VPC Flow Logs in Cloud Logging and Security Command Center to detect malicious traffic patterns.
Cloud Armor security policies can be attached to an external HTTP(S) load balancer to provide Google's edge DDoS mitigation and configurable WAF rules for the OWASP Top 10, satisfying the first requirement. Cloud IDS is a Google-managed, agentless intrusion-detection service that is deployed as regional endpoints inside a VPC subnet and inspects mirrored traffic for command-and-control, malware, and other threats, fulfilling the second requirement while avoiding the operational burden of managing your own IDS infrastructure. The other options either rely on self-managed tooling, do not provide WAF protection, or do not deliver inline threat detection.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Cloud Armor and how does it help with DDoS protection?
Open an interactive chat with Bash
What is Cloud IDS and how does it detect threats?
Open an interactive chat with Bash
What are the OWASP Top 10 and why are they important?
Open an interactive chat with Bash
What is Cloud Armor, and how does it provide DDoS mitigation and WAF protection?
Open an interactive chat with Bash
What is Cloud IDS, and how does it work without host agents?
Open an interactive chat with Bash
How does the external HTTP(S) Load Balancer integrate with Cloud CDN and Cloud Armor?
Open an interactive chat with Bash
GCP Professional Cloud Architect
Managing and provisioning a solution infrastructure
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .