How to Secure a GCP Web App with Firewalls, WAF, and IDS?
Your organization hosts a sensitive web application in Google Cloud. To protect the web application, you've set up a virtual private cloud (VPC) with dedicated subnets for the application's frontend and backend components. You must implement security controls to restrict incoming traffic, protect against web-based attacks, and monitor internal traffic. What should you do?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests your knowledge of mapping specific GCP security services to distinct traffic vectors (external restriction, web-layer protection, and internal monitoring) while avoiding the trap of misassigning WAF or firewall capabilities.
This guide explains how to implement a defense-in-depth strategy for sensitive GCP web applications using Cloud Firewall, Cloud Armor, and Cloud IDS. It establishes why option A is the correct configuration for restricting access, blocking web threats, and monitoring internal traffic.
Option C is frequently chosen due to confusion between IAP and Cloud Armor; however, IAP controls application-level access rather than blocking automated web attacks, and Cloud Armor cannot monitor internal VPC traffic.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option A correctly aligns each required security control with its designated GCP service. Cloud Firewall enforces network-level restrictions by permitting only allow-listed traffic. Google Cloud Armor acts as a managed web application firewall at the load balancer edge to block vulnerabilities like SQL injection. Cloud IDS inspects encrypted and unencrypted traffic across the VPC to identify internal anomalies.Why the Other Options Are Wrong
Option B incorrectly assigns DNSSEC to web attack mitigation, when it only secures DNS resolution. Option C misplaces Cloud Armor as an internal traffic monitor and confuses IAP’s identity enforcement with broad web-layer protection. Option D swaps responsibilities by assigning web attack detection to Cloud IDS and internal monitoring to Cloud Armor, which are fundamentally mismatched capabilities.Community Comment Notes
Learners consistently validate option A by mapping the scenario requirements to service functions. As Pime13 noted, the solution works because "protects against common web-based attacks such as DDoS and SQL injection by using predefined rules" while the firewall handles access control. The consensus highlights that mastering these distinct service boundaries prevents configuration overlap during the exam.Official Reference
Exam Strategy
Always map each requirement in the scenario directly to a single GCP service before evaluating options. Remember that Cloud Firewall handles network-layer restrictions, Cloud Armor is strictly a web application firewall (WAF) at the load balancer, and Cloud IDS inspects both ingress and internal east-west traffic for anomalies.
Frequently Asked Questions
Why can't Cloud Armor monitor internal traffic?
Cloud Armor operates exclusively at the external load balancer edge to filter HTTP/HTTPS requests. Internal east-west traffic bypasses this boundary and requires Cloud IDS for inspection.
Does DNSSEC replace web application firewall rules?
No. DNSSEC only validates DNS record authenticity to prevent spoofing. It provides zero protection against SQL injection, XSS, or other application-layer attacks.