CV0-004 Security Practice Question
A healthcare company runs a web application on Google Cloud. A security analyst notices that attackers are submitting crafted SQL statements through the application's search form and reading data from the backend database. The company wants to block these requests before they reach the application servers while keeping false positives low for legitimate search traffic. Which service should be implemented?
⚠ Common exam trap
The trap here is assuming that any Google Cloud network security service inspects application payloads, when only Cloud Armor evaluates HTTP request content for SQL injection signatures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud Armor security policy with a preconfigured WAF rule for SQL injection attached to the backend service.
The attack arrives as HTTP requests carrying SQL syntax, so the control must inspect request content at the edge. Cloud Armor with a preconfigured WAF rule for SQL injection evaluates requests against the backend service and can block matching traffic, with preview mode available to tune sensitivity. VPC Service Controls, Cloud IDS, and Private Service Connect operate at network or detection layers and cannot stop the payload.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Cloud Armor security policy with a preconfigured WAF rule for SQL injection attached to the backend service.
Why this is correct
Cloud Armor inspects incoming requests at the edge and can apply preconfigured WAF rules, including the SQL injection signature set, before traffic reaches the backend. Rules can run in preview mode first so the team tunes sensitivity and reduces false positives on legitimate search strings. This directly blocks the crafted statements at the perimeter.
- ✗
Cloud IDS endpoint deployed in the application subnet to detect intrusion attempts.
Why it's wrong here
Cloud IDS performs deep packet inspection and raises alerts on intrusion signatures, but it is a detection service rather than an inline blocker for application-layer SQL injection. It would generate findings after the traffic passed, and it does not parse the search form parameters, so it does not meet the goal of blocking requests before they reach the servers.
- ✗
VPC Service Controls perimeter around the database project to restrict data exfiltration.
Why it's wrong here
VPC Service Controls define a security perimeter around Google Cloud services to prevent data exfiltration and unauthorized access across projects, but they do not inspect HTTP request payloads for SQL syntax. The malicious statements would still reach the application and the database, so this control does not block the attack described.
- ✗
Private Service Connect endpoint that exposes the database only to the application's VPC.
Why it's wrong here
Private Service Connect lets consumers reach a service through an internal endpoint without traversing the public internet, which reduces network exposure. It does not examine application payloads, so a crafted SQL statement submitted through the legitimate endpoint still reaches the database. This addresses network topology, not request content inspection.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.