🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 54 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your public e-commerce site sits behind a global external HTTP(S) load balancer. A recent attack sent millions of HTTP POST requests from thousands of IPs, exhausting back-ends, while logs showed SQL injection and cross-site-scripting probes. You need a Google-managed defense that 1) automatically detects and stops large Layer-7 DDoS floods with no manual tuning, 2) blocks common OWASP Top-10 threats, and 3) requires no change to the current load-balancer architecture. Which Cloud Armor-based action satisfies all requirements?

  • Attach a Cloud Armor security policy to the load balancer's backend service, enable Adaptive Protection, and activate Google-managed preconfigured WAF rules in blocking mode.

  • Enable Cloud Armor in preview (monitoring-only) mode and manually review logs daily to add new custom rules when attacks occur.

  • Create a Cloud Armor security policy that contains only a deny rule listing the botnet's source IP addresses.

  • Replace the external HTTP(S) load balancer with an internal HTTP(S) load balancer and use VPC firewall rules to filter malicious requests.

GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot