Cloud Digital Leader Google Cloud Products and Services Practice Question
A company is building a microservices architecture on Google Kubernetes Engine (GKE). They need to expose services externally with HTTPS, distribute traffic across the cluster, and protect against DDoS attacks. Which THREE Google Cloud services should they combine? (Choose THREE)
⚠ Common exam trap
The trap is including Cloud DNS or VPC firewall rules as part of the traffic distribution and protection solution; candidates must distinguish name resolution and network-level filtering from the edge services that actually load balance, cache, and defend against DDoS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud CDN
Cloud Load Balancing (E) is correct because it provides the external HTTPS load balancer that fronts the GKE services, terminates TLS, and distributes incoming traffic across the cluster's nodes and pods. Cloud Armor (D) is correct because it attaches to the external load balancer's backend service to provide WAF rules and Layer 3/4/7 DDoS protection, including Google Cloud's edge-based network DDoS mitigation. Cloud CDN (C) is correct because it caches content at Google's global edge locations, reducing origin load and absorbing traffic spikes, which complements the load balancer and helps mitigate volumetric attacks. Cloud DNS (A) is not required for this scenario since it only resolves domain names and does not distribute traffic or provide DDoS protection, and VPC firewall rules (B) operate at the network level within the VPC but do not expose services externally over HTTPS or defend against DDoS at the edge.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cloud DNS
Why it's wrong here
Cloud DNS resolves domain names to addresses but neither terminates HTTPS, load-balances traffic across GKE pods, nor absorbs DDoS floods; those need a load balancer with managed certificates and Cloud Armor. Cloud DNS is the right choice when the requirement is simply publishing and resolving a custom domain.
- ✗
VPC firewall rules
Why it's wrong here
VPC firewall rules filter traffic by IP, port, and protocol at the network layer, but they cannot terminate HTTPS, distribute requests across pods, or mitigate volumetric DDoS attacks. They are tempting because they are a core GKE security control, and correct when the need is restricting which sources may reach cluster nodes.
- ✓
Cloud CDN
Why this is correct
Cloud CDN caches content at Google's global edge points of presence, absorbing volumetric traffic before it reaches your GKE backends. This directly satisfies the DDoS protection constraint: attack requests terminate at edge locations rather than consuming cluster resources, while also reducing origin load and latency for externally exposed HTTPS services.
- ✓
Cloud Armor
Why this is correct
Cloud Armor provides edge-layer DDoS protection and web application firewall filtering, absorbing volumetric attacks before they reach GKE workloads. It integrates with external HTTP(S) load balancing, satisfying the stem's explicit DDoS mitigation requirement while traffic is distributed across the cluster.
- ✓
Cloud Load Balancing
Why this is correct
Cloud Load Balancing terminates HTTPS and distributes traffic across GKE pods, satisfying both the external HTTPS exposure and traffic distribution requirements. Its global anycast front end also absorbs volumetric attacks before they reach the cluster.
Visual reference
Go deeper
Related to this question
Learn chapter
Private Service Connect and Private Access
Key term
Denial-of-service
A Denial-of-service (DoS) attack is an attempt to make a computer, network, or online service unavailable to its intended users by overwhelming it with fake traffic or requests.
Key term
Hypertext Transfer Protocol Secure
Hypertext Transfer Protocol Secure, or HTTPS, is the secure version of HTTP that encrypts data between a web browser and a website using SSL/TLS to protect sensitive information like passwords and credit card numbers.
About these practice questions
Courseiva writes every GCDL question from scratch — 848 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.