GCP Professional Cloud Security Engineer Practice Question
Your e-commerce platform is fronted by an external HTTP(S) load balancer protected by Cloud Armor. Logs show credential-stuffing bots sending bursts of more than 50 POST requests per minute to the /login endpoint from the same source IP address. Legitimate customers rarely exceed 10 login attempts per minute, and other paths such as /catalog must not be throttled. You need to block offending IPs for 15 minutes once they exceed the threshold, without affecting normal traffic. Which Cloud Armor configuration best satisfies these requirements?
Add a Cloud Armor rate-based rule that matches requests where the path starts with /login and the method is POST, sets a threshold of 50 requests per 60 seconds per client IP, and applies a deny action with a 900-second ban.
Create an allow rule that permits only 10 requests per minute to /login and place a lower-priority default deny rule for all other traffic.
Enable Cloud Armor Adaptive Protection in standard mode so that it automatically throttles excessive traffic across all URLs.
Populate a Cloud Armor denylist with attacker IP addresses obtained from a daily refreshed threat-intelligence feed targeting the login service.
A rate-based Cloud Armor rule can monitor the request rate coming from each source IP and automatically enforce temporary bans. Matching only POST requests to the /login path ensures that catalog browsing and other application traffic are unaffected. Setting the threshold to 50 requests in a 60-second interval reflects observed malicious behavior, while leaving headroom for legitimate users who stay below 10 requests per minute. Choosing the default enforce-on-key of client IP groups requests per attacker, and specifying a deny action with a 900-second (15-minute) ban blocks further attempts during the cooling-off period.
Adaptive Protection (often tuned for volumetric L7 DDoS) does not provide deterministic per-IP rate bans. Limiting to 10 requests per minute would disrupt legitimate users during peak activity. Manually maintaining a denylist or relying on daily threat-intel updates cannot react quickly enough to stop real-time brute-force bursts.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a rate-based Cloud Armor rule, and how does it work?
Open an interactive chat with Bash
What is Cloud Armor Adaptive Protection used for, and why wouldn’t it work in this scenario?
Open an interactive chat with Bash
How does the enforce-on-key option in Cloud Armor rules operate?
Open an interactive chat with Bash
What is Cloud Armor in GCP?
Open an interactive chat with Bash
What are rate-based rules in Cloud Armor?
Open an interactive chat with Bash
How does the 900-second ban work in Cloud Armor?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .