Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 493 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 493

Select 2Google Cloud Platform

Your organization is using Google Cloud Armor to protect a web application deployed on Google Cloud. You are tasked with configuring bot management to block known malicious bots while allowing legitimate traffic. Which steps should you take to achieve this?

  1. A

    Enable the preconfigured WAF rule for known malicious bots in the Cloud Armor security policy.

  2. B

    Use a custom firewall rule with IP address filtering to block known bot networks.

  3. C

    Enable reCAPTCHA Enterprise in the Cloud Armor security policy to challenge suspicious traffic.

  4. D

    Create a rate-based rule to automatically block any IP addresses with a high request rate.

  5. E

    Review Google Cloud Armor logs to manually identify and block malicious IPs.

Show answer and explanation

Correct answers: A, C

Explanation

To configure bot management effectively in Google Cloud Armor, you should leverage preconfigured WAF rules for known malicious bots and advanced features like reCAPTCHA Enterprise to handle suspicious traffic. These options provide scalable and automated protection without requiring manual intervention. Other approaches like custom IP filtering or manual log review are less efficient and not recommended for this use case.

  • A. Correct.

    Correct: Enabling the preconfigured WAF rule for known malicious bots in Cloud Armor automatically blocks traffic from known malicious bots using Google's threat intelligence.

  • B. Incorrect.

    Incorrect: While using custom IP filtering can block specific bots, it is not scalable or effective compared to Google's preconfigured WAF rule for bot management.

  • C. Correct.

    Correct: Enabling reCAPTCHA Enterprise in Cloud Armor allows you to challenge suspicious traffic, ensuring that legitimate users can proceed while bots are blocked.

  • D. Incorrect.

    Incorrect: Rate-based rules are better suited for mitigating Denial of Service attacks, not specifically for identifying and blocking bots.

  • E. Incorrect.

    Incorrect: Reviewing logs manually is not an efficient or scalable way to manage bots, especially when automated solutions are available.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam