The origin should not be a public address. Visitors terminate at Cloud CDN. The origin answers the shield, not the internet at large. That is protection even before a named DDoS feature.

Address space

Point the public hostname at the distribution. Restrict origin pull. If the old A record still works, attackers will use it.

L3-L7 in the path

Cloud CDN includes L3-L7 DDoS mitigation, TLS 1.3, access policies and token authentication on a 200+ Tbps network. Junk is absorbed off-origin.

Application rules are still yours

This is not a promise of every WAF signature you might want. Review current controls. Combine with origin-side auth.

DNS floods are a different layer

If the zone is on Cloud DNS, authority is DDoS-protected Anycast too. A CDN cannot save a name that does not resolve.