easyMultiple Choice
Google ACE Practice Question: Expose a web application running on Compute…
A company wants to expose a web application running on Compute Engine instances behind a managed instance group. They need a single IP address that distributes incoming HTTP traffic across instances. Which type of load balancer should they use?
⚠ Common exam trap
Candidates often confuse the External HTTP(S) Load Balancer with the External TCP/UDP Network Load Balancer, mistakenly thinking that any load balancer with an external IP can handle HTTP traffic, but the Network Load Balancer lacks Layer 7 features and is not optimized for HTTP workloads.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
External HTTP(S) Load Balancer
The External HTTP(S) Load Balancer is a regional or global, proxy-based Layer 7 load balancer that provides a single external IP address for distributing incoming HTTP traffic across Compute Engine instances in a managed instance group. It supports HTTP and HTTPS protocols, health checks, and autoscaling, making it ideal for web applications.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Internal TCP/UDP Load Balancer
Why it's wrong here
This regional load balancer operates at Layer 4 and only supports traffic from clients that are inside the same VPC and region. It does not get an external IP address, so internet clients cannot reach the web application through it. Since the use case requires exposing the app to external users, this option is incorrect.
- ✗
External TCP/UDP Network Load Balancer
Why it's wrong here
This proxy forwards raw TCP/UDP packets and does not inspect HTTP payloads, making it incapable of routing by URL path, hostname, or header. Although it has an external IP, it lacks Layer 7 features like SSL termination and cookie-based affinity that are essential for a web application. Therefore, it is not the right choice for HTTP-based web traffic.
- ✗
SSL Proxy Load Balancer
Why it's wrong here
This load balancer is intended for non-HTTP TCP protocols that need SSL offloading, such as database or proprietary traffic. It terminates TLS but then forwards decrypted TCP packets without understanding HTTP methods, URLs, or headers, so it cannot perform content-based routing. For a web application served over HTTP/HTTPS, an L7 HTTP(S) load balancer is required.
- ✓
External HTTP(S) Load Balancer
Why this is correct
This global Layer 7 load balancer is purpose-built for HTTP and HTTPS traffic, supporting URL path and host-based routing, SSL termination, and integration with Cloud CDN. It provides a single external anycast IP address to all clients and intelligently distributes requests to backend web servers. This meets the company's requirement to expose an external web application with a single IP.
Go deeper
Related to this question
Learn chapter
Cloud Run and App Engine
Key term
IP address
An IP address is a unique numerical label assigned to each device connected to a computer network that uses the Internet Protocol for communication.
Key term
Compute Engine
Compute Engine is Google Cloud's Infrastructure-as-a-Service (IaaS) offering that lets you create and run virtual machines on Google's infrastructure.
About these practice questions
This ACE question is part of Courseiva's 775-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.