Cloud Digital Leader Practice Question: Google Cloud products, services, and solutions
A retail company runs a customer-facing web application on Compute Engine instances. The security team wants to protect the application from common web exploits such as SQL injection and cross-site scripting, and also wants to mitigate distributed denial-of-service (DDoS) attacks without modifying the application code. Which Google Cloud service should the company implement to meet these requirements?
⚠ Common exam trap
The trap here is assuming that identity-based access controls such as Identity-Aware Proxy or API perimeters such as VPC Service Controls can substitute for payload inspection and volumetric attack mitigation at the edge.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud Armor
Cloud Armor is the correct choice because it is the Google Cloud edge security service that integrates with external HTTP(S) load balancers to deliver WAF filtering and DDoS protection. Its preconfigured rules defend against OWASP Top 10 threats like SQL injection and cross-site scripting, and its rate-based and adaptive protection rules absorb volumetric attacks. Because enforcement happens at the load balancer, the application itself remains unchanged, meeting every requirement in the scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
VPC Service Controls
Why it's wrong here
VPC Service Controls creates a security perimeter around Google Cloud APIs and services to prevent data exfiltration, such as stopping BigQuery data from being copied to an unauthorized project. It does not inspect inbound HTTP request payloads, so it cannot detect SQL injection or cross-site scripting attempts, and it has no DDoS mitigation capability at the network edge. It addresses data exfiltration risk, not the inbound web exploit and availability threat described.
- ✓
Cloud Armor
Why this is correct
Cloud Armor is Google Cloud's edge security service that works with external HTTP(S) load balancers to filter malicious traffic. It provides preconfigured WAF rules based on OWASP ModSecurity signatures that block SQL injection and cross-site scripting, plus adaptive protection and rate-based rules to absorb and mitigate DDoS attacks. Because it operates at the load balancer layer, no application code changes are required, directly satisfying both the WAF and DDoS requirements.
- ✗
Cloud Identity-Aware Proxy
Why it's wrong here
Identity-Aware Proxy (IAP) enforces identity and context-based access control before requests reach an application, which is ideal for protecting internal tools and administrative interfaces. It authenticates users rather than inspecting request payloads, so it does not block SQL injection or cross-site scripting signatures. IAP also does not provide volumetric DDoS absorption, meaning it cannot fulfill the availability protection the scenario requires.
- ✗
Cloud NAT
Why it's wrong here
Cloud NAT allows resources without external IP addresses to initiate outbound connections to the internet while preventing unsolicited inbound connections. It is an egress translation service, not a security inspection layer, so it cannot evaluate HTTP request content for SQL injection or cross-site scripting. It also provides no DDoS mitigation for inbound traffic, making it irrelevant to protecting the public web application described.
Go deeper
Related to this question
Learn chapter
GitOps and Infrastructure as Code
Key term
SQL
SQL is a standard programming language used to manage, query, and manipulate relational databases by issuing commands like SELECT, INSERT, UPDATE, and DELETE.
Key term
Service
A service is a software component or system that performs a specific function and is available to be used by other programs or users over a network.
About these practice questions
This GCDL question is part of Courseiva's 848-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.