Google Cloud Professional Cloud Network Engineer — Question 221

You recently reviewed the user behavior for your main application, which uses an external global Application Load Balancer, and found that the backend servers were overloaded due to erratic spikes in the rate of client requests. You need to limit the concurrent sessions and return an HTTP 429 Too Many Requests response back to the client while following Google-recommended practices. What should you do?

Answer options

Correct answer: A

Explanation

Option A is correct because it directly implements a security policy using Cloud Armor to throttle requests and return HTTP 429 responses, which aligns with Google’s best practices. Option B does not provide a mechanism to send a 429 response and focuses on scaling backend servers instead. Option C applies predefined OWASP rules, but it may not specifically address the need for a 429 response. Option D involves manual configuration on a VM, which is not as efficient or scalable as using Cloud Armor.