Professional Cloud DevOps Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
Your organization is experiencing a distributed Layer 7 denial-of-service attack targeting backend services behind an external Application Load Balancer. Google Cloud Armor Adaptive Protection generates an alert along with a suggested mitigation rule containing a specific Common Expression Language (CEL) expression.
You need to evaluate and remediate this security threat to minimize service risk while ensuring legitimate customer traffic is not inadvertently blocked due to false positives. How should you deploy the suggested recommendation to evaluate its operational impact safely?
Create a placeholder rule with evaluateAdaptiveProtectionAutoDeploy() set directly to a deny action at the lowest possible priority.
Deploy an Organization Policy constraint via Security Command Center to block the attacking IP ranges across the organization.
Create a security policy rule with the suggested CEL expression, place it in preview mode, and set its priority higher than baseline allow rules.
Enable predictive autoscaling on the backend Managed Instance Group to absorb the excess attack traffic with additional compute resources.
Create a placeholder rule with evaluateAdaptiveProtectionAutoDeploy() set directly to a deny action at the lowest possible priority.
Deploy an Organization Policy constraint via Security Command Center to block the attacking IP ranges across the organization.
Create a security policy rule with the suggested CEL expression, place it in preview mode, and set its priority higher than baseline allow rules.
Google Cloud Armor Adaptive Protection detects anomalous Layer 7 traffic patterns and automatically generates suggested security rules containing tailored Common Expression Language (CEL) expressions. Deploying a rule in preview mode instructs Cloud Armor to evaluate incoming traffic against the rule and write audit logs without taking active enforcement actions (such as dropping or rejecting traffic).
Preview mode provides the necessary balance between rapid threat response and operational safety. It offers definitive telemetry on rule accuracy while preventing catastrophic disruption of valid customer workloads.
Enable predictive autoscaling on the backend Managed Instance Group to absorb the excess attack traffic with additional compute resources.