Courseiva
mediumMultiple Select

Google ACE Cloud Armor security policy Practice Question

A company uses Cloud Armor to protect an HTTP Load Balancer. They want to allow traffic only from specific IP ranges (198.51.100.0/24 and 203.0.113.0/24) and block common web attacks like SQL injection and XSS. Which TWO actions should they take?

⚠ Common exam trap

Candidates often confuse VPC firewall rules with Cloud Armor; candidates might think network firewall rules can block SQL injection, but they operate at lower layers and cannot inspect HTTP payloads. Also, some might forget the default deny rule, assuming the allow rule alone is sufficient.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable predefined WAF rules (e.g., OWASP Top 10) in the Cloud Armor security policy.

Option D is correct because Cloud Armor security policies are enforced at the HTTP(S) Load Balancer edge, so an allow rule matching source IP ranges 198.51.100.0/24 and 203.0.113.0/24 combined with a default deny rule (priority-based, with the allow rule at a lower priority number) restricts traffic to only those ranges. Option C is correct because Cloud Armor's predefined WAF rules, such as the OWASP Top 10 rule sets (e.g., sqli-v33-stable and xss-v33-stable), detect and block SQL injection and XSS at the load balancer. Option A is incorrect because Cloud NAT only provides outbound internet access for instances without external IPs and does not filter inbound traffic or block web attacks. Option B is incorrect because VPC firewall rules operate at the network/subnet level on instance traffic, not on HTTP(S) Load Balancer traffic, and cannot inspect for SQL injection or XSS. Option E is incorrect because Cloud CDN only caches static content to improve latency and does not enforce IP allowlisting or WAF protections.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set up Cloud NAT to provide outbound internet access for the instances.

    Why it's wrong here

    Cloud NAT provides outbound internet connectivity for instances without external IP addresses; it does not filter inbound requests to a load balancer or inspect HTTP payloads. The scenario requires Cloud Armor security policies enforcing IP allowlists and WAF rules at the load balancer's backend service. Cloud NAT would be correct for egress-only private instances needing software updates.

  • ✗

    Configure VPC firewall rules on the subnet to allow only the IP ranges.

    Why it's wrong here

    VPC firewall rules filter traffic at the subnet or instance level by IP, port and protocol, and cannot inspect HTTP request bodies for SQL injection or XSS signatures. Cloud Armor attaches to the backend service of the HTTP Load Balancer, where both the IP allowlist and WAF rules must be applied. Firewall rules suit network-layer segmentation, not layer 7 filtering.

  • ✓

    Enable predefined WAF rules (e.g., OWASP Top 10) in the Cloud Armor security policy.

    Why this is correct

    Predefined WAF rules at Cloud Armor's layer 7 evaluate request payloads against signatures for SQL injection and cross-site scripting. This satisfies the stem's requirement to block common web attacks, which IP-based allow rules alone cannot inspect or mitigate.

  • ✓

    Create a Cloud Armor security policy with an allow rule for the IP ranges and a default deny rule for all other traffic.

    Why this is correct

    The security policy's allow rule matches the two specified CIDR ranges, while the default deny rule drops everything else, enforcing the stem's allowlist constraint. Cloud Armor evaluates rules by priority, so this pairing restricts traffic to only the permitted source networks.

  • ✗

    Enable Cloud CDN to cache static content from the backend.

    Why it's wrong here

    Cloud CDN caches static assets at edge locations; it neither evaluates source IP ranges nor inspects HTTP payloads for SQL injection or XSS. Cloud Armor security policies with IP-based allow rules and the preconfigured WAF ruleset handle both requirements at the load balancer. CDN would be chosen to reduce latency and origin egress for cacheable content.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 775 original ACE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.