Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 471 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 471

Select 3Google Cloud Platform

Your company hosts a high-traffic e-commerce website on Google Cloud. Recently, the site has been targeted by large-scale volumetric DDoS attacks. You want to implement advanced DDoS protection to ensure minimal impact on the website while keeping operational costs manageable. Which of the following actions should you take to secure your site?

  1. A

    Enable Cloud Armor and configure security policies to block abnormal traffic patterns.

  2. B

    Set up a Cloud Load Balancer and enable autoscaling to handle traffic spikes caused by DDoS attacks.

  3. C

    Use VPC firewall rules to block all traffic from unknown IP addresses.

  4. D

    Enable Google Cloud CDN to cache content and reduce the load on backend services during attacks.

  5. E

    Migrate the website to a private GKE cluster and restrict access using internal IPs only.

Show answer and explanation

Correct answers: A, B, D

Explanation

To protect against DDoS attacks on a public-facing e-commerce site, you should use a combination of Cloud Armor for advanced DDoS protection, Cloud Load Balancer with autoscaling to handle traffic spikes, and Google Cloud CDN to cache content and reduce backend load. These services work together to ensure availability and performance during attacks. Blocking all unknown IPs or restricting access using internal IPs is not feasible for public-facing websites.

  • A. Correct.

    Cloud Armor provides advanced DDoS protection by allowing you to define security policies that prevent malicious traffic from reaching your application. This is a recommended action.

  • B. Correct.

    Cloud Load Balancer with autoscaling can absorb traffic spikes, including those caused by DDoS attacks, and distribute traffic effectively across backend services. This helps mitigate the attack’s impact.

  • C. Incorrect.

    Blocking all traffic from unknown IPs in VPC firewall rules is not practical because it may block legitimate users, especially on a public-facing website.

  • D. Correct.

    Enabling Google Cloud CDN caches content closer to the users, reducing the load on backend services during attacks. This is an effective strategy to mitigate DDoS impacts.

  • E. Incorrect.

    Migrating a public-facing e-commerce website to a private GKE cluster with internal IPs only would make the website inaccessible to external users, which is not a feasible solution.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam