Cloud Digital Leader Google Cloud Security Practice Question
A security team needs to detect and alert on suspicious outbound network traffic from their GCP environment, such as data exfiltration attempts. They require a managed service that analyzes traffic for threats. Which service should they use?
⚠ Common exam trap
GCDL often tests the confusion between Cloud IDS (managed network threat detection) and Security Command Center (posture/finding aggregation) — candidates pick SCC thinking it 'analyzes traffic' when it only aggregates findings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud IDS
Cloud IDS is Google Cloud's managed network intrusion detection service that inspects traffic (via packet mirroring) for threats such as malware, command-and-control, and data exfiltration, and generates alerts. It is purpose-built for detecting suspicious network activity in a GCP environment without deploying third-party appliances.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cloud Armor
Why it's wrong here
Cloud Armor is a web application firewall (WAF) that protects inbound HTTP(S) traffic to external Application Load Balancers, using policies such as IP allow/deny lists, geo-blocking, and OWASP signature rules. It operates only on traffic destined for your load-balanced front ends, with no visibility into server-initiated outbound connections or raw network packets. Therefore, it cannot detect suspicious outbound anomalies.
- ✗
Security Command Center
Why it's wrong here
Security Command Center (SCC) is Google Cloud's security and risk management hub that centralizes findings, vulnerability assessments, and compliance posture across your assets, but it does not capture or inspect network packets itself. It receives telemetry and findings from other detection services, such as Cloud IDS, Cloud Armor, or third-party scanners, to present a consolidated view. Consequently, SCC lacks the packet-level visibility needed to independently identify suspicious outbound traffic on a network.
- ✓
Cloud IDS
Why this is correct
Cloud IDS is a managed intrusion detection service that uses packet mirroring in your VPC to copy traffic and apply deep packet inspection with threat signatures against full bidirectional flows, including outbound communications. Because it evaluates connections initiated from your workloads, it can detect command-and-control callbacks, outbound malware propagation, and data exfiltration attempts in near real time. This makes Cloud IDS the appropriate choice for detecting and alerting on suspicious outbound network behavior.
- ✗
Chronicle
Why it's wrong here
Chronicle is a cloud-native security analytics platform (a SIEM) that ingests, normalizes, and correlates logs and other telemetry from many sources after the events have occurred, enabling historical search and rules-based detection. It does not inspect live network traffic at the packet level; instead, it depends on upstream services to generate logs or findings from network inspection. As a result, Chronicle cannot directly alert on real-time outbound anomalies unless another tool such as Cloud IDS first captures and forwards the relevant network telemetry.
Go deeper
Related to this question
Learn chapter
Looker Studio (Data Studio) for Visualisation
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Service
A service is a software component or system that performs a specific function and is available to be used by other programs or users over a network.
About these practice questions
One of 848 original GCDL practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.