⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All AWS & Cloud Architecture Interview Questions Scenario 139 of 186 in AWS & Cloud Architecture
Senior DevOps / SRE GCP & Cloud Cloud Security & WAF Production Runbook

Q: A sudden Layer 7 HTTP flood (300,000 req/sec) targets your login API on GCP, degrading backend Cloud Run and GKE services. How do you deploy and tune Cloud Armor to block the attack in real-time without rejecting legitimate customers?

Production implementation of Google Cloud Armor security policies, rate-limiting rules, Adaptive Protection ML anomaly detection, and OWASP Top 10 mitigation on Global External HTTP(S) Load Balancers.

#GCP #Cloud Armor #WAF #DDoS #Load Balancing #Security
🎙️ Candidate Opening & Architectural Context
"During a promotional launch, our checkout API experienced a sophisticated Layer 7 HTTP flood from distributed IP addresses that bypassed traditional rate limiters. We leveraged Cloud Armor to neutralize the attack at the Google edge network."
Advertisement
⚡ Recommended Practice Lab

Want to master this scenario in a live sandbox? Stephane Maarek's AWS Certified DevOps Engineer Professional Masterclass on Udemy covers this exact problem with hands-on terminal drills.

🛠️ Production Runbook & Step-by-Step Resolution

1️⃣

Analyze Edge Telemetry in Cloud Monitoring & Log Explorer

Inspect Cloud Load Balancing access logs to identify request fingerprinting patterns:

  • Log Query: Ran httpRequest.requestUrl=~'/api/v1/auth/login' AND httpRequest.status=504 in Cloud Logging.
  • Fingerprinting: Isolated anomalous User-Agent signatures, JA3 TLS fingerprints, and source ASN concentrations.
  • Target Backend: Verified backend service saturation on the GKE Ingress controller.
Pro Tip: Cloud Armor operates at the Google Front End (GFE) edge, absorbing traffic before it ever reaches your VPC or cluster nodes.
2️⃣

Enable Cloud Armor Adaptive Protection

Leverage Google's machine learning anomaly detection to auto-generate mitigation rules:

  • Enable ML: Executed gcloud compute security-policies update prod-armor-policy --enable-layer7-ddos-defense.
  • Alert Review: Evaluated the auto-generated Cloud Armor security policy alert containing the calculated attack signature.
Pro Tip: Adaptive Protection compares live traffic against baseline patterns to automatically recommend precise rule signatures.
3️⃣

Deploy Threshold Rate-Limiting Rules

Apply strict client-based rate limits on sensitive endpoints using Cloud Armor rules:

  • Action: Configured throttle action when a client exceeds 50 requests per minute on /api/v1/auth/login.
  • Ban Action: Added ban-threshold to temporarily drop repeat offenders for 10 minutes (returning HTTP 429).
  • Key Extraction: Keyed by Client IP (SRC_IP) and enforced Google reCAPTCHA Enterprise challenge for suspicious tokens.
Pro Tip: Use Preview Mode (preview=true) first to verify rule hit rates before switching the enforcement action to deny or throttle.
4️⃣

Enforce Pre-Configured WAF Rulesets (OWASP CRS 3.3)

Protect the backend against SQLi, XSS, and Remote Code Execution:

  • SQLi Mitigation: Added evaluatePreconfiguredWaf('sqli-v33-stable', {'sensitivity': 1}).
  • Geo-Restriction: Blocked high-risk non-operational regions while allowing verified CDN/partner IP blocks.
Pro Tip: Tune sensitivity levels to 1 initially to prevent false positives in APIs accepting JSON payloads with SQL-like terminology.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Cloud Armor protects services at the Google global edge network, neutralizing multi-gigabit DDoS floods and L7 attacks before traffic ever enters your VPC or consumes cluster compute resources."
⚡ 60-Second Elevator Pitch Talking Points
  • Analyzed edge access logs to identify attack URL patterns, TLS signatures, and ASN concentrations.
  • Enabled Cloud Armor Adaptive Protection to calculate machine-learning traffic signatures automatically.
  • Deployed rate-limiting and client throttling rules returning HTTP 429 for IPs exceeding 50 req/min on sensitive login routes.
  • Enforced preconfigured OWASP Core Rulesets for SQL injection and cross-site scripting mitigation.
Advertisement
Want more AWS & Cloud Architecture scenarios?
Explore our complete collection of scenario-based AWS & Cloud Architecture interview runbooks.
Browse All AWS & Cloud Architecture Questions →