Courseiva

CV0-004 Cloud Architecture and Design Practice Question

A cloud engineer is deploying a new web application on Google Cloud. The application must be reachable from the internet on HTTP and HTTPS, and the engineer wants Google's global edge network to terminate TLS and route users to the closest healthy backend. The backend instances should not be directly exposed to the internet. Which Google Cloud service should the engineer use?

⚠ Common exam trap

It's easy for candidates to confuse Cloud NAT, which handles outbound-only traffic, with a load balancer that accepts inbound client connections.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cloud Load Balancing with an external Application Load Balancer and a managed SSL certificate.

An external Application Load Balancer is the Google Cloud service that provides global Layer 7 load balancing, TLS termination with managed certificates, health-checked routing to the nearest backend, and private backends. Cloud NAT, passthrough network load balancing, and Cloud CDN each address different concerns and cannot fulfill the full set of requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cloud CDN with a signed URL configuration pointing directly at the backend instance group.

    Why it's wrong here

    Cloud CDN caches content at the edge but must be attached to a load balancer frontend to receive traffic; it is not a standalone entry point. Signed URLs control access to cached objects, not TLS termination or routing to healthy backends, so this does not satisfy the design.

  • ✗

    A regional external passthrough Network Load Balancer with backend VMs that have public IP addresses.

    Why it's wrong here

    A passthrough Network Load Balancer operates at Layer 4 and does not terminate TLS or provide HTTP-aware routing. Requiring public IPs on the backend VMs also directly exposes them to the internet, violating the requirement that backends not be publicly reachable.

  • ✓

    Cloud Load Balancing with an external Application Load Balancer and a managed SSL certificate.

    Why this is correct

    An external Application Load Balancer is a global Layer 7 service that terminates TLS at Google's edge, routes requests to the nearest healthy backend, and supports managed certificates. Backends can be private instances, so they are not directly exposed to the internet, matching all stated requirements.

  • ✗

    Cloud NAT with a regional external IP address, allowing backend instances to serve traffic directly.

    Why it's wrong here

    Cloud NAT provides outbound internet access for instances without external IP addresses; it does not accept or route inbound client connections. Using it to expose a web application is not possible, and it provides no TLS termination, health checking, or global routing.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.