Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 461 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 461

Select 2Google Cloud Platform

Your organization is hosting a web application on Google Cloud using a backend service with an HTTPS load balancer. To protect your application from common web vulnerabilities like SQL injection and cross-site scripting (XSS), you need to implement Web Application Firewall (WAF) rules. What steps should you take to achieve this using Google Cloud Armor?

  1. A

    Create a Google Cloud Armor security policy and attach it to the backend service.

  2. B

    Enable the preconfigured WAF rules for SQL injection and cross-site scripting in the security policy.

  3. C

    Write custom WAF rules in the security policy using regular expressions.

  4. D

    Attach the Google Cloud Armor security policy directly to the HTTPS load balancer.

  5. E

    Enable the 'Block All Traffic' mode in Google Cloud Armor to filter all malicious requests.

Show answer and explanation

Correct answers: A, B

Explanation

To protect your web application from vulnerabilities like SQL injection and XSS using Google Cloud, you need to create a Cloud Armor security policy, enable the preconfigured WAF rules for those vulnerabilities, and attach the policy to the backend service. Custom rules and 'Block All Traffic' mode are either unnecessary or inappropriate for this scenario.

  • A. Correct.

    Correct: A Google Cloud Armor security policy must be created and attached to the backend service to enforce WAF rules.

  • B. Correct.

    Correct: Google Cloud Armor provides preconfigured WAF rules for common vulnerabilities like SQL injection and XSS, which can be enabled in the security policy.

  • C. Incorrect.

    Incorrect: While custom rules can be created, Google Cloud Armor provides preconfigured rules for common vulnerabilities, so this step is unnecessary for SQL injection and XSS protection.

  • D. Incorrect.

    Incorrect: Google Cloud Armor security policies are attached to backend services, not directly to HTTPS load balancers.

  • E. Incorrect.

    Incorrect: 'Block All Traffic' mode is not a valid method for implementing WAF rules and would disrupt all legitimate traffic.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam