exam questions

Exam Professional Cloud Security Engineer All Questions

View all questions & answers for the Professional Cloud Security Engineer exam

Exam Professional Cloud Security Engineer topic 1 question 6 discussion

Actual exam question from Google's Professional Cloud Security Engineer
Question #: 6
Topic #: 1
[All Professional Cloud Security Engineer Questions]

A customer needs to launch a 3-tier internal web application on Google Cloud Platform (GCP). The customer's internal compliance requirements dictate that end- user access may only be allowed if the traffic seems to originate from a specific known good CIDR. The customer accepts the risk that their application will only have SYN flood DDoS protection. They want to use GCP's native SYN flood protection.
Which product should be used to meet these requirements?

  • A. Cloud Armor
  • B. VPC Firewall Rules
  • C. Cloud Identity and Access Management
  • D. Cloud CDN
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
KILLMAD
Highly Voted 4 years, 9 months ago
Answer is A
upvoted 16 times
...
zanhsieh
Most Recent 1 day, 10 hours ago
Selected Answer: A
I will still stick with A since Cloud Armor supports regional internal application load balancer: https://cloud.google.com/load-balancing/docs/l7-internal#backend-features https://cloud.google.com/load-balancing/docs/l7-internal/int-https-lb-tf-examples Also the question does not ask for cross region, Cloud Armor should be an easier and safer bet.
upvoted 1 times
...
BPzen
1 month, 1 week ago
Selected Answer: A
Cloud Armor: This service is specifically designed for web application and API protection. It allows you to configure rules based on IP addresses (CIDR ranges), and it includes built-in DDoS protection, including SYN flood protection. This directly addresses the customer's requirements. Here's why the other options are not the best fit: B. VPC Firewall Rules: These are primarily for controlling traffic within your VPC network. While you can restrict traffic based on IP addresses, they don't offer the advanced DDoS protection capabilities of Cloud Armor.
upvoted 1 times
...
3d9563b
5 months ago
Selected Answer: B
VPC Firewall Rules will allow you to control access based on CIDR ranges, ensuring that only traffic from the specified IP addresses is permitted. Additionally, GCP provides built-in SYN flood protection as part of its infrastructure. This solution aligns with both the internal compliance requirements and the acceptance of the risk regarding SYN flood attacks.
upvoted 2 times
...
alilikpo
6 months, 2 weeks ago
Selected Answer: B
While Cloud Armor offers advanced DDoS protection, it's not the most suitable choice for restricting access based on known good CIDRs in this scenario. Cloud Armor excels at mitigating volumetric DDoS attacks like SYN floods, but its access control mechanisms aren't specifically designed for CIDR-based whitelisting.
upvoted 4 times
...
charlesdeng
8 months ago
Selected Answer: B
For internal web application, it shall be used by VPC Firewall Rules
upvoted 2 times
...
ppandher
1 year, 2 months ago
Can Cloud Armor be used for INTERNAL Applications ? I think - NO, as it is used for External attacks- so Answer should be - B VPC Firewall Rules. Verified from ChatGPT3.5
upvoted 4 times
...
mildi
1 year, 5 months ago
Answer A if no Load balancer used
upvoted 1 times
mildi
1 year, 5 months ago
I mean B if no load balancer used
upvoted 1 times
...
...
pfilourenco
1 year, 6 months ago
Selected Answer: A
Answer is A
upvoted 1 times
...
ppandey96
1 year, 8 months ago
Selected Answer: A
https://cloud.google.com/blog/products/identity-security/how-google-cloud-blocked-largest-layer-7-ddos-attack-at-46-million-rps
upvoted 1 times
...
civilizador
1 year, 10 months ago
https://cloud.google.com/files/GCPDDoSprotection-04122016.pdf It doesn't say a word about cloud Armor in the context of DDoS attacks because it is not the main feature of Cloud Armor. In the DDoS mitigation best practices only mentioned Load Balancer, Firewall rules and CDN. So I don't know if it is either Firewall rules or CDN. Most likely Firewall rules since CDN doesn't directly prevent the attack more like distributes it through multiple global endpoints. Little bit tricky question.
upvoted 1 times
civilizador
1 year, 6 months ago
The question clearly indicates that request should be allowed only if originating from a specific CIDR so the answer is a firewall rules
upvoted 2 times
...
...
shetniel
1 year, 10 months ago
It is an internal web application and they need to allow access only for user traffic originated from a specific CIDR. They are fine with just default SYN flood protection. This can very well be handled by a VPC firewall rule.
upvoted 4 times
...
alestrix
1 year, 11 months ago
Selected Answer: B
For CIDR check the firewall is sufficient and SYN flood protection is already given by the regular load balancer in front of the service. Armor gives much more than just SYN flood protection and given the statement "their application will only have SYN flood DDoS protection" this is another vote against Armor.
upvoted 2 times
gcpengineer
1 year, 7 months ago
the External Load Balancer (LB) does not provide built-in protection against SYN flood DDoS attacks
upvoted 1 times
...
...
Alokep
2 years ago
Answer A
upvoted 1 times
...
AzureDP900
2 years, 1 month ago
Cloud Armor
upvoted 1 times
...
Premumar
2 years, 1 month ago
Selected Answer: A
Cloud Armor
upvoted 1 times
...
AwesomeGCP
2 years, 2 months ago
Selected Answer: A
A. Cloud Armor
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago