Courseiva

Cloud Digital Leader Google Cloud Products and Services Practice Question

An organization runs a multi-region web application behind a global external HTTP(S) load balancer. They want to protect against DDoS attacks and filter traffic based on IP reputation and request headers. Which service should they integrate with the load balancer?

⚠ Common exam trap

GCDL often tests whether candidates confuse Cloud CDN (caching) with Cloud Armor (security) — both sit at the edge but only Cloud Armor filters traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cloud Armor

Cloud Armor is Google Cloud's edge security service that attaches to global external HTTP(S) load balancers and provides WAF rules, IP reputation/denylists, geo-blocking, and header-based filtering. It's the native integration point for DDoS and Layer 7 filtering at the load balancer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Cloud Armor

    Why this is correct

    Cloud Armor is the correct choice because it provides web application firewall (WAF) capabilities, DDoS protection, and IP reputation filtering at the global edge, directly integrated with Cloud Load Balancing. It can inspect HTTP(S) traffic, block malicious requests based on Layer 7 attributes like headers and body, and enforce allow/deny lists based on IP addresses and geolocation. This gives the organization precise, policy-based control over incoming traffic before it reaches backend instances.

  • ✗

    Cloud CDN

    Why it's wrong here

    Cloud CDN is incorrect for this requirement because it is primarily a content delivery network that caches static and dynamic content at globally distributed edge locations to reduce latency and origin load. While it can help absorb some volumetric DDoS traffic due to its cache footprint, it does not perform security inspection, WAF rule evaluation, or IP reputation filtering. Cloud CDN works alongside Cloud Armor for acceleration and protection, but it cannot replace the security controls needed to filter malicious requests.

  • ✗

    VPC firewall rules

    Why it's wrong here

    VPC firewall rules are not the right tool for edge-based DDoS protection or IP reputation filtering because they operate at the instance network interface level, within the VPC, and control traffic based on IP addresses, ports, and protocols. They do not parse HTTP content or evaluate application-layer attributes, and they lack the global scale and edge enforcement point required to stop attacks before they consume network resources. Additionally, firewall rules are often stateful but cannot distinguish between legitimate traffic and a DDoS attack based on reputation or request patterns.

  • ✗

    Cloud NAT

    Why it's wrong here

    Cloud NAT is incorrect because it provides outbound-only Internet access for virtual machine instances that do not have external IP addresses, translating their private IPs to a public IP for egress traffic. It does not inspect inbound traffic, apply security policies, or provide DDoS protection—in fact, it is not even applicable to inbound traffic directed at a load-balanced web application. Cloud NAT is purely a connectivity service, not a security or filtering service, so it cannot meet the organization's requirement for edge security.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every GCDL question from scratch — 848 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.