What's changed: Created Professional Cloud Network Engineer Chapter 6 (Domain 6 "Network security": Google Cloud Armor = edge/backend policies/WAF (SQLi/XSS/RFI)/advanced DDoS and Adaptive Protection/rate limiting/bot management/Threat Intelligence; Cloud NGFW/VPC firewall = strategy/hierarchical/effective policy/L7 inspection (Enterprise)/migration/rule criteria (priority/protocol/direction/source-destination)/logging/micro-segmentation (secure tags/SA/network tags)/tiers (Essentials/Standard/Enterprise); public Cloud NAT (auto-manual IP/static-dynamic ports); Secure Web Proxy; self-managed NVA (multi-NIC/internal LB next hop/policy-based routes)/out-of-band Network Security Integration/Packet Mirroring).
6.1Cloud Armor and Cloud NGFW / VPC firewall
Understand Google Cloud Armor policies (edge/backend security policies, WAF (SQLi/XSS/RFI), advanced network DDoS and Adaptive Protection, rate limiting, bot management, Threat Intelligence) and Cloud NGFW/VPC firewall rules (firewall strategy, hierarchical firewall, effective policy, L7 inspection (NGFW Enterprise), migration from VPC rules, rule criteria (priority/protocol/direction/source/destination), firewall logging, micro-segmentation, NGFW tiers (Essentials/Standard/Enterprise)).
Configure network security on two fronts: the "edge" (public boundary) and "inside" (in-VPC traffic). Cloud Armor handles the edge; Cloud NGFW/VPC firewall handles the inside.
6.1.1Google Cloud Armor
Google Cloud Armor applies security policies in front of an external Application LB. Distinguish edge security policies (before CDN/cache) from backend security policies (per backend service). Block known attacks with WAF rules (preconfigured rules for SQL injection, cross-site scripting, remote file inclusion, etc.), and prepare for large-scale attacks with advanced network DDoS protection and Adaptive Protection (ML-learned anomalies with suggested mitigations). Strengthen rules with rate limiting (per-source flow control), bot management (reCAPTCHA integration), and Threat Intelligence (known malicious IPs/Tor, etc.). Map "protect public web from WAF/DDoS = Cloud Armor."
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

