Managed instance group autoscaled to its max under bursty traffic (suspected DDoS) behind a network load balancer. Quickly restore user transactions while minimizing cost. Which two actions should you take?
Choose an answer
Tap an option to check your answer.
Correct answer: Use Cloud Armor to blacklist the attacker's IP addresses., Create a global HTTP(S) load balancer and move your application backend to it..
Why this is the answer
To quickly restore user transactions and minimize cost during a suspected DDoS attack, implementing Cloud Armor is crucial. Cloud Armor provides DDoS protection and web application firewall (WAF) capabilities, allowing you to blacklist attacker IP addresses and filter malicious traffic before it reaches your backend instances, thus reducing the load and cost. Creating a global HTTP(S) load balancer and moving your application backend to it is also effective because HTTP(S) load balancers integrate natively with Cloud Armor and offer advanced traffic management and DDoS mitigation features at the edge of Google's network, further protecting your application. Increasing the autoscaling maximum backend size would incur higher costs without addressing the malicious traffic. Shutting down the application would stop all transactions, legitimate and illegitimate. SSHing into instances for log inspection is a reactive troubleshooting step, not a proactive or immediate mitigation for a DDoS attack.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed