Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise is deploying a mission-critical web application on Google Kubernetes Engine (GKE) and Compute Engine virtual machines behind a global external Application Load Balancer. The organization requires a multi-layered network security design that satisfies the following requirements:
Which combination of Google Cloud security services and configurations should you deploy?
Attach a Google Cloud Armor security policy with preconfigured WAF rules to the external Application Load Balancer backend service, and configure Cloud NGFW intrusion detection/threat prevention with security profiles applied to firewall policy rules in the VPC network.
Enable Cloud NAT on the VPC network for DDoS mitigation, and configure Packet Mirroring to forward mirrored traffic to Cloud Key Management Service (Cloud KMS) for deep packet inspection.
Deploy Identity-Aware Proxy (IAP) on the external Application Load Balancer for OWASP filtering, and apply Cloud Armor security policies directly to the internal VPC subnets for intrusion detection.
Configure standard VPC firewall ingress deny rules matching malicious source IP ranges on the backend instances, and enable VPC Flow Logs with Cloud Logging alert policies for deep packet inspection.
Attach a Google Cloud Armor security policy with preconfigured WAF rules to the external Application Load Balancer backend service, and configure Cloud NGFW intrusion detection/threat prevention with security profiles applied to firewall policy rules in the VPC network.
Google Cloud Armor is an edge-based Web Application Firewall (WAF) and DDoS mitigation service integrated directly into Google Cloud's external load-balancing infrastructure. Cloud Next Generation Firewall (Cloud NGFW) with intrusion detection and threat prevention capabilities provides managed Layer 7 deep packet inspection inside the Virtual Private Cloud (VPC) network.
This architecture establishes true defense-in-depth by pairing edge-based Layer 7 filtering via Google Cloud Armor with in-VPC packet inspection via Cloud NGFW threat prevention profiles.
Enable Cloud NAT on the VPC network for DDoS mitigation, and configure Packet Mirroring to forward mirrored traffic to Cloud Key Management Service (Cloud KMS) for deep packet inspection.
Deploy Identity-Aware Proxy (IAP) on the external Application Load Balancer for OWASP filtering, and apply Cloud Armor security policies directly to the internal VPC subnets for intrusion detection.
Configure standard VPC firewall ingress deny rules matching malicious source IP ranges on the backend instances, and enable VPC Flow Logs with Cloud Logging alert policies for deep packet inspection.