Courseiva

Cloud Digital Leader Google Cloud Products and Services Practice Question

A company is building a microservices architecture on Google Kubernetes Engine (GKE). They need to expose services externally with HTTPS, distribute traffic across the cluster, and protect against DDoS attacks. Which THREE Google Cloud services should they combine? (Choose THREE)

⚠ Common exam trap

The trap is including Cloud DNS or VPC firewall rules as part of the traffic distribution and protection solution; candidates must distinguish name resolution and network-level filtering from the edge services that actually load balance, cache, and defend against DDoS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cloud CDN

Cloud Load Balancing (E) is correct because it provides the external HTTPS load balancer that fronts the GKE services, terminates TLS, and distributes incoming traffic across the cluster's nodes and pods. Cloud Armor (D) is correct because it attaches to the external load balancer's backend service to provide WAF rules and Layer 3/4/7 DDoS protection, including Google Cloud's edge-based network DDoS mitigation. Cloud CDN (C) is correct because it caches content at Google's global edge locations, reducing origin load and absorbing traffic spikes, which complements the load balancer and helps mitigate volumetric attacks. Cloud DNS (A) is not required for this scenario since it only resolves domain names and does not distribute traffic or provide DDoS protection, and VPC firewall rules (B) operate at the network level within the VPC but do not expose services externally over HTTPS or defend against DDoS at the edge.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cloud DNS

    Why it's wrong here

    Cloud DNS resolves domain names to addresses but neither terminates HTTPS, load-balances traffic across GKE pods, nor absorbs DDoS floods; those need a load balancer with managed certificates and Cloud Armor. Cloud DNS is the right choice when the requirement is simply publishing and resolving a custom domain.

  • ✗

    VPC firewall rules

    Why it's wrong here

    VPC firewall rules filter traffic by IP, port, and protocol at the network layer, but they cannot terminate HTTPS, distribute requests across pods, or mitigate volumetric DDoS attacks. They are tempting because they are a core GKE security control, and correct when the need is restricting which sources may reach cluster nodes.

  • ✓

    Cloud CDN

    Why this is correct

    Cloud CDN caches content at Google's global edge points of presence, absorbing volumetric traffic before it reaches your GKE backends. This directly satisfies the DDoS protection constraint: attack requests terminate at edge locations rather than consuming cluster resources, while also reducing origin load and latency for externally exposed HTTPS services.

  • ✓

    Cloud Armor

    Why this is correct

    Cloud Armor provides edge-layer DDoS protection and web application firewall filtering, absorbing volumetric attacks before they reach GKE workloads. It integrates with external HTTP(S) load balancing, satisfying the stem's explicit DDoS mitigation requirement while traffic is distributed across the cluster.

  • ✓

    Cloud Load Balancing

    Why this is correct

    Cloud Load Balancing terminates HTTPS and distributes traffic across GKE pods, satisfying both the external HTTPS exposure and traffic distribution requirements. Its global anycast front end also absorbs volumetric attacks before they reach the cluster.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Go deeper

Related to this question

About these practice questions

Courseiva writes every GCDL question from scratch — 848 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.