The origin should not be a public address. Visitors terminate at Cloud CDN. The origin answers the shield, not the internet at large. That is protection even before a named DDoS feature.
Address space
Point the public hostname at the distribution. Restrict origin pull. If the old A record still works, attackers will use it.
L3-L7 in the path
Cloud CDN includes L3-L7 DDoS mitigation, TLS 1.3, access policies and token authentication on a 200+ Tbps network. Junk is absorbed off-origin.
Application rules are still yours
This is not a promise of every WAF signature you might want. Review current controls. Combine with origin-side auth.
DNS floods are a different layer
If the zone is on Cloud DNS, authority is DDoS-protected Anycast too. A CDN cannot save a name that does not resolve.
