How to Secure a GCP Web App with Firewalls, WAF, and IDS?

GCP Network & Web Security
Answer Correct answer: A — Use Cloud Firewall to restrict access, Cloud Armor to block web attacks, and Cloud IDS to monitor internal traffic anomalies.

Your organization hosts a sensitive web application in Google Cloud. To protect the web application, you've set up a virtual private cloud (VPC) with dedicated subnets for the application's frontend and backend components. You must implement security controls to restrict incoming traffic, protect against web-based attacks, and monitor internal traffic. What should you do?

  1. Configure Cloud Firewall to permit allow-listed traffic only, deploy Google Cloud Armor with predefined rules for blocking common web attacks, and deploy Cloud Intrusion Detection System (IDS) to detect internal traffic anomalies. Correct Answer
  2. Configure Google Cloud Armor to allow incoming connections, configure DNS Security Extensions (DNSSEC) on Cloud DNS to secure against common web attacks, and deploy Cloud Intrusion Detection System (Cloud IDS) to detect internal traffic anomalies.
  3. Configure Cloud Intrusion Detection System (Cloud IDS) to monitor incoming connections, deploy Identity-Aware Proxy (IAP) to block common web attacks, and deploy Google Cloud Armor to detect internal traffic anomalies.
  4. Configure Cloud DNS to secure incoming traffic, deploy Cloud Intrusion Detection System (Cloud IDS) to detect common web attacks, and deploy Google Cloud Armor to detect internal traffic anomalies.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests your knowledge of mapping specific GCP security services to distinct traffic vectors (external restriction, web-layer protection, and internal monitoring) while avoiding the trap of misassigning WAF or firewall capabilities.

This guide explains how to implement a defense-in-depth strategy for sensitive GCP web applications using Cloud Firewall, Cloud Armor, and Cloud IDS. It establishes why option A is the correct configuration for restricting access, blocking web threats, and monitoring internal traffic.

Option C is frequently chosen due to confusion between IAP and Cloud Armor; however, IAP controls application-level access rather than blocking automated web attacks, and Cloud Armor cannot monitor internal VPC traffic.

Community Discussion (3 comments)

Pime13 👍 1 Selected: A
Here's why: Cloud Firewall: By configuring the firewall to permit only allow-listed traffic, you can restrict incoming traffic to only trusted sources, enhancing security. Google Cloud Armor: This service provides protection against common web-based attacks such as DDoS and SQL injection by using predefined rules. Cloud Intrusion Detection System (IDS): Deploying IDS helps in monitoring internal traffic for any anomalies, ensuring that any suspicious activity within the VPC is detected and addressed promptly. This combination of services provides a comprehensive security posture for your sensitive web application, addressing both external and internal threats.
MoAk 👍 1 Selected: A
A is good.
yokoyan 👍 2 Selected: A
I think it's A.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option A correctly aligns each required security control with its designated GCP service. Cloud Firewall enforces network-level restrictions by permitting only allow-listed traffic. Google Cloud Armor acts as a managed web application firewall at the load balancer edge to block vulnerabilities like SQL injection. Cloud IDS inspects encrypted and unencrypted traffic across the VPC to identify internal anomalies.

Why the Other Options Are Wrong

Option B incorrectly assigns DNSSEC to web attack mitigation, when it only secures DNS resolution. Option C misplaces Cloud Armor as an internal traffic monitor and confuses IAP’s identity enforcement with broad web-layer protection. Option D swaps responsibilities by assigning web attack detection to Cloud IDS and internal monitoring to Cloud Armor, which are fundamentally mismatched capabilities.

Community Comment Notes

Learners consistently validate option A by mapping the scenario requirements to service functions. As Pime13 noted, the solution works because "protects against common web-based attacks such as DDoS and SQL injection by using predefined rules" while the firewall handles access control. The consensus highlights that mastering these distinct service boundaries prevents configuration overlap during the exam.

Official Reference

Exam Strategy

Always map each requirement in the scenario directly to a single GCP service before evaluating options. Remember that Cloud Firewall handles network-layer restrictions, Cloud Armor is strictly a web application firewall (WAF) at the load balancer, and Cloud IDS inspects both ingress and internal east-west traffic for anomalies.

Frequently Asked Questions

Why can't Cloud Armor monitor internal traffic?

Cloud Armor operates exclusively at the external load balancer edge to filter HTTP/HTTPS requests. Internal east-west traffic bypasses this boundary and requires Cloud IDS for inspection.

Does DNSSEC replace web application firewall rules?

No. DNSSEC only validates DNS record authenticity to prevent spoofing. It provides zero protection against SQL injection, XSS, or other application-layer attacks.

Related Analysis

← Back to PCSE Study Guide