Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 463 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 463

Select 2Google Cloud Platform

You are a Google Cloud Network Engineer tasked with securing a web application hosted on Google Cloud. The application is exposed to the internet through an external HTTP(S) load balancer, and you suspect that attackers are attempting to exploit vulnerabilities like SQL injection and cross-site scripting (XSS). Which steps should you take to implement a Web Application Firewall (WAF) to protect the application?

  1. A

    Enable Cloud Armor and create a security policy with preconfigured WAF rules to block SQL injection and XSS attacks.

  2. B

    Add a backend bucket to the load balancer and configure it to use Cloud Storage for WAF rules.

  3. C

    Associate the Cloud Armor security policy with the HTTP(S) load balancer frontend.

  4. D

    Manually update the application code to handle SQL injection and XSS filtering.

  5. E

    Enable the built-in Google Cloud Firewall Rules to detect and block SQL injection and XSS attacks.

Show answer and explanation

Correct answers: A, C

Explanation

To protect against application-layer threats such as SQL injection and cross-site scripting (XSS), you should use Cloud Armor with preconfigured WAF rules. These rules are specifically designed to detect and block such vulnerabilities. Enabling Cloud Armor and associating its security policy with the HTTP(S) load balancer ensures that these protections are applied to incoming traffic before it reaches your application. Other options, such as Google Cloud Firewall Rules or backend buckets, do not provide application-layer protection and are not applicable to this scenario.

  • A. Correct.

    Correct: Enabling Cloud Armor and using preconfigured WAF rules is the appropriate way to protect against SQL injection and XSS attacks in Google Cloud. Cloud Armor offers preconfigured rule sets for these types of vulnerabilities.

  • B. Incorrect.

    Incorrect: Backend buckets and Cloud Storage are not related to implementing WAF rules. Cloud Storage is used for hosting static assets, not for security purposes.

  • C. Correct.

    Correct: Associating the Cloud Armor security policy with the HTTP(S) load balancer frontend ensures that the WAF rules are applied to incoming traffic before it reaches the backend.

  • D. Incorrect.

    Incorrect: While updating the application code to handle SQL injection and XSS is a good practice, it is not a direct implementation of WAF rules. WAF rules in Google Cloud are managed through Cloud Armor.

  • E. Incorrect.

    Incorrect: Google Cloud Firewall Rules are used to manage network-level access (e.g., IP or port restrictions) but do not have the capability to detect or block application-layer threats like SQL injection or XSS.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam