CV0-004 Cloud Architecture and Design Practice Question
A cloud engineer is deploying a new web application on Google Cloud. The application must be reachable from the internet on HTTP and HTTPS, and the engineer wants Google's global edge network to terminate TLS and route users to the closest healthy backend. The backend instances should not be directly exposed to the internet. Which Google Cloud service should the engineer use?
⚠ Common exam trap
It's easy for candidates to confuse Cloud NAT, which handles outbound-only traffic, with a load balancer that accepts inbound client connections.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud Load Balancing with an external Application Load Balancer and a managed SSL certificate.
An external Application Load Balancer is the Google Cloud service that provides global Layer 7 load balancing, TLS termination with managed certificates, health-checked routing to the nearest backend, and private backends. Cloud NAT, passthrough network load balancing, and Cloud CDN each address different concerns and cannot fulfill the full set of requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cloud CDN with a signed URL configuration pointing directly at the backend instance group.
Why it's wrong here
Cloud CDN caches content at the edge but must be attached to a load balancer frontend to receive traffic; it is not a standalone entry point. Signed URLs control access to cached objects, not TLS termination or routing to healthy backends, so this does not satisfy the design.
- ✗
A regional external passthrough Network Load Balancer with backend VMs that have public IP addresses.
Why it's wrong here
A passthrough Network Load Balancer operates at Layer 4 and does not terminate TLS or provide HTTP-aware routing. Requiring public IPs on the backend VMs also directly exposes them to the internet, violating the requirement that backends not be publicly reachable.
- ✓
Cloud Load Balancing with an external Application Load Balancer and a managed SSL certificate.
Why this is correct
An external Application Load Balancer is a global Layer 7 service that terminates TLS at Google's edge, routes requests to the nearest healthy backend, and supports managed certificates. Backends can be private instances, so they are not directly exposed to the internet, matching all stated requirements.
- ✗
Cloud NAT with a regional external IP address, allowing backend instances to serve traffic directly.
Why it's wrong here
Cloud NAT provides outbound internet access for instances without external IP addresses; it does not accept or route inbound client connections. Using it to expose a web application is not possible, and it provides no TLS termination, health checking, or global routing.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.