CCSP Cloud Security Operations Practice Question
A cloud security engineer is deploying a web application on Google Cloud Platform (GCP) and needs to protect it from common web exploits like SQL injection and cross-site scripting. The engineer wants a managed service that can be configured with security policies. Which GCP service should be used?
⚠ Common exam trap
The trap here is assuming that Cloud Load Balancing includes WAF capabilities, but it requires Cloud Armor for that purpose.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Google Cloud Armor
Google Cloud Armor is the correct service because it is a managed WAF that can be configured with security policies to protect against web exploits. It integrates with load balancing to filter malicious traffic. The other services provide identity control, network connectivity, or load distribution, but none offer WAF functionality.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Google Cloud Armor
Why this is correct
Google Cloud Armor is a managed web application firewall (WAF) that provides protection against common web vulnerabilities such as SQL injection and cross-site scripting. It integrates with HTTP(S) load balancing and allows you to define security policies with rules to filter traffic. This matches the requirement for a managed service to protect the web application.
- ✗
Google Cloud Load Balancing
Why it's wrong here
Cloud Load Balancing distributes incoming traffic across multiple instances to ensure availability and scalability. While it can integrate with Cloud Armor, it does not itself provide WAF capabilities. It does not inspect or filter traffic for web exploits. Therefore, it cannot fulfill the requirement to protect the web application from SQL injection and XSS.
- ✗
Google Cloud VPN
Why it's wrong here
Cloud VPN securely connects on-premises networks to GCP via IPsec tunnels. It operates at the network layer and does not inspect application-layer traffic for web exploits. It is used for secure network connectivity, not for protecting web applications from attacks like SQL injection. Thus, it is not the appropriate service for this scenario.
- ✗
Google Cloud Identity-Aware Proxy (IAP)
Why it's wrong here
IAP controls access to applications based on user identity and context, providing zero-trust access. It does not inspect web traffic for exploits like SQL injection or XSS. While it enhances security by verifying user identity, it is not a WAF and cannot block application-layer attacks. Therefore, it does not meet the requirement to protect against common web exploits.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.