Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 474 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 474

Select 3Google Cloud Platform

Your organization has deployed a web application hosted in Google Cloud behind an HTTPS load balancer. Recently, the application has been targeted by a volumetric DDoS attack that exhausts the available backend resources. You need to configure advanced network DDoS protection to mitigate the attack without affecting legitimate traffic. What steps should you take to configure protection using Google Cloud's features?

  1. A

    Enable Cloud Armor and configure a security policy to block traffic from known malicious IP addresses.

  2. B

    Set up Google Cloud's Network Telemetry to monitor and automatically block anomalous traffic in real time.

  3. C

    Configure rate limiting rules in Cloud Armor to limit the number of requests per second from individual IP addresses.

  4. D

    Enable the 'Global External HTTP(S) Load Balancer DDoS Protection' feature by default, which automatically mitigates volumetric DDoS attacks.

  5. E

    Use VPC Service Controls to isolate backend services from external traffic entirely.

Show answer and explanation

Correct answers: A, C, D

Explanation

To configure advanced network DDoS protection, you need to leverage multiple Google Cloud features. Cloud Armor provides robust protection through IP blocking and rate limiting, which can filter out malicious traffic and prevent resource exhaustion. Additionally, the Global External HTTP(S) Load Balancer includes built-in DDoS protection to handle large-scale attacks. Combining these features ensures effective mitigation without affecting legitimate traffic.

  • A. Correct.

    Correct. Enabling Cloud Armor and using a security policy to block known malicious IPs is an essential step in protecting against DDoS attacks. Cloud Armor integrates with threat intelligence to identify harmful traffic sources.

  • B. Incorrect.

    Incorrect. While monitoring traffic is useful, Google Cloud's Network Telemetry does not automatically block anomalous traffic. Specific configurations, like Cloud Armor policies, are required for blocking.

  • C. Correct.

    Correct. Rate limiting rules in Cloud Armor are effective in mitigating volumetric DDoS attacks by controlling the number of requests that a single IP address can send to your application.

  • D. Correct.

    Correct. The Global External HTTP(S) Load Balancer natively includes DDoS protection for volumetric attacks, which helps mitigate large-scale traffic floods without requiring additional configuration.

  • E. Incorrect.

    Incorrect. While VPC Service Controls enhance security by preventing unauthorized access to backend services, they are not designed for mitigating DDoS attacks on public-facing applications.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam