Skip to main content

Frequently Asked Questions

What specifically does Cloud Armor protect that the load balancer itself doesn't?

A Global External HTTP(S) Load Balancer distributes traffic but doesn't inspect request content for malicious patterns on its own — Cloud Armor sits in front of it as a security policy layer, evaluating each request against rate-based rules (blocking a single IP that exceeds a request threshold) and preconfigured WAF rule sets (blocking SQL injection, XSS, and other OWASP-style attack signatures) before the request ever reaches a backend. Without Cloud Armor, the load balancer would happily forward a SQL injection attempt straight to your application.

What's a common mistake when first enabling Cloud Armor's preconfigured WAF rules?

Deploying preconfigured rules directly in blocking mode without first running them in preview/dry-run mode against real traffic. WAF rules pattern-match on request content, and legitimate traffic — a support form with SQL-like text in a comment field, or a search query with special characters — can trigger false positives and get blocked outright. Teams that skip the preview phase find real users getting 403s with no visibility into why, since the block happens before the request reaches application-level logging.