Cloud Digital Leader Google Cloud Products and Services Practice Question
A security engineer wants to block malicious traffic patterns at the edge of Google's network before it reaches their application. Which service should they configure?
⚠ Common exam trap
The trap is confusing network-layer firewalls (VPC firewall rules) with application-layer WAF (Cloud Armor). Candidates may pick VPC firewall rules because they think it blocks malicious traffic, but it lacks HTTP inspection and edge enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud Armor
Cloud Armor is Google Cloud's edge security service that provides WAF capabilities and DDoS protection, allowing you to block malicious traffic patterns before they reach your application. It integrates with global load balancing to filter requests at the edge of Google's network. This directly addresses the requirement to block malicious traffic at the edge.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
VPC firewall rules
Why it's wrong here
VPC firewall rules are stateful L3/L4 filters that apply to individual VM instances via network tags or service accounts. They evaluate packets based on source/destination IP, port, and protocol, but do not inspect application payloads or recognize malicious patterns in HTTP requests. Because they are enforced at the VM's virtual NIC rather than the network edge, attack traffic still reaches the network before being allowed or denied.
- ✗
Cloud DNS
Why it's wrong here
Cloud DNS is a managed domain name resolution service that translates hostnames into IP addresses. It acts only as an authoritative DNS server for your domains and does not sit in the data path of actual traffic, so it cannot inspect, filter, or block packets or HTTP request patterns. Malicious traffic would bypass Cloud DNS entirely and reach your backends without any interception or analysis.
- ✗
Cloud CDN
Why it's wrong here
Cloud CDN is a distributed caching layer that stores static content at Google's edge locations to reduce latency and egress costs. While it terminates requests, its primary purpose is to serve cached responses; it does not evaluate request content for attack signatures such as SQLi, XSS, or bot patterns. It can work alongside a WAF when configured with Cloud Armor, but Cloud CDN alone lacks web application firewall capabilities and cannot block malicious traffic based on request semantics.
- ✓
Cloud Armor
Why this is correct
Cloud Armor is a global DDoS mitigation and web application firewall (WAF) service that enforces security policies at the edge of Google's network, in front of load balancers. It supports CEL-based custom rules that can inspect headers, query parameters, and request bodies to block specific malicious patterns like SQL injection, cross-site scripting, or known bot signatures. Because policies are evaluated before traffic reaches your GCE instances or GKE pods, attack traffic can be dropped with minimal latency impact, making it the correct choice for blocking a malicious traffic pattern.
Visual reference
Go deeper
Related to this question
Learn chapter
Cloud CDN and Google's Global Network
Key term
WAF
A Web Application Firewall (WAF) is a security tool that filters, monitors, and blocks HTTP traffic to and from a web application to protect it from common attacks.
Key term
Google Cloud
Google Cloud is a suite of cloud computing services offered by Google that provides infrastructure, platform, and software solutions over the internet.
About these practice questions
Courseiva writes every GCDL question from scratch — 848 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.