You want to apply a Cloud Armor policy to a GKE‑deployed application. Which GKE resource should be the policy target?
Choose an answer
Tap an option to check your answer.
Correct answer: GKE Ingress.
Why this is the answer
Cloud Armor policies protect applications from various web-based attacks. To apply a Cloud Armor policy to a GKE-deployed application, you must target a GKE Ingress resource. The Ingress acts as the entry point for external traffic into your cluster, allowing Cloud Armor to inspect and filter requests before they reach your application pods. Targeting a GKE Node or GKE Pod directly is incorrect because Cloud Armor operates at the load balancing layer, not at the individual node or pod level. While a GKE Cluster encompasses your application, it's too broad; Cloud Armor policies are applied to specific HTTP(S) Load Balancers, which are provisioned by Ingress resources in GKE.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed