You must deploy a Cloud Armor WAF policy to protect an internet-facing website hosted on Compute Engine. Where should you attach the Cloud Armor security policy to enforce WAF rules on incoming HTTP(S) requests?
Choose an answer
Tap an option to check your answer.
Correct answer: Attach the security policy to the backend service of the external HTTP(S) load balancer.
Why this is the answer
Cloud Armor security policies are designed to protect applications by filtering incoming HTTP(S) traffic. Attaching the policy to the backend service of an external HTTP(S) load balancer is the correct approach because the load balancer is the entry point for internet-facing HTTP(S) traffic to your Compute Engine instances. This ensures all web traffic is inspected before reaching your application. Attaching it to the VPC network as a firewall rule is incorrect because firewall rules operate at a lower network layer (Layer 3/4) and cannot inspect HTTP(S) traffic for WAF functionalities. Attaching it to the network interface of each VM instance is not how Cloud Armor policies are applied; Cloud Armor integrates with load balancing services. Attaching it directly to Cloud CDN configuration is incorrect because Cloud CDN is a caching service, and while it works with load balancers, Cloud Armor policies are applied at the load balancer's backend service, not directly to CDN.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed