Courseiva
hardMultiple Choice

Google ACE Practice Question: Deploying a multi-region application on Google…

A company is deploying a multi-region application on Google Kubernetes Engine (GKE) with clusters in us-central1 and europe-west1. They want to route user traffic to the closest healthy cluster using a global load balancer with SSL termination. Which load balancing service should they use?

⚠ Common exam trap

Many candidates confuse regional load balancers (like SSL Proxy or TCP/UDP Network LB) with global ones, mistakenly thinking SSL termination alone is sufficient, but the key requirement for multi-region routing to the closest cluster demands a global load balancer with a global backend service.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

External HTTPS Load Balancer with a global backend service (using NEGs)

D is correct because the External HTTPS Load Balancer with a global backend service using Network Endpoint Groups (NEGs) provides global anycast IP, SSL termination, and traffic routing to the closest healthy GKE cluster via Google's global network. This meets the requirement for multi-region GKE clusters with automatic failover and low latency.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Internal Load Balancer

    Why it's wrong here

    An internal load balancer distributes traffic only within a VPC or region and provides no global anycast VIP or SSL termination at the edge. It suits private in-cluster service exposure; multi-region external routing needs a global external Application Load Balancer.

  • ✗

    SSL Proxy Load Balancer

    Why it's wrong here

    SSL Proxy is for non-HTTP traffic and does not integrate with GKE NEGs.

  • ✗

    External TCP/UDP Network Load Balancer

    Why it's wrong here

    External TCP/UDP Network Load Balancer operates at layer 4, so it cannot terminate SSL or inspect HTTP host/path to select the closest healthy cluster. It is tempting because it provides regional, non-proxied passthrough load balancing for TCP/UDP traffic, which suits non-HTTP protocols or when client-side TLS termination is required.

  • ✓

    External HTTPS Load Balancer with a global backend service (using NEGs)

    Why this is correct

    A global external HTTPS load balancer with a global backend service and NEGs provides anycast VIP, SSL termination and health-based proximity routing across both regions. This satisfies the requirement to send users to the closest healthy GKE cluster.

About these practice questions

This ACE question is part of Courseiva's 775-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.