GCP PCA · Question 36 · Ensure solution and operations reliability
Your company hosts a public-facing web application on GKE behind a Global External HTTP(S) Load Balancer. You notice a sudden spike in traffic originating from a specific country, which is causing performance degradation. The traffic appears to be a Layer 7 DDoS attack. How can you quickly mitigate this?
Answer options:
Update the VPC Firewall rules to block the IP ranges of the specific country.
Create a Cloud Armor security policy to deny traffic from the specific country and attach it to the Load Balancer's backend service.
Configure Identity-Aware Proxy (IAP) to require user authentication.
Scale up the GKE cluster to absorb the attack.
50 questions · hints · full answers · grading