Courseiva
easyMultiple Choice

Google ACE Practice Question: Expose a web application running on Compute…

A company wants to expose a web application running on Compute Engine instances behind a managed instance group. They need a single IP address that distributes incoming HTTP traffic across instances. Which type of load balancer should they use?

⚠ Common exam trap

Candidates often confuse the External HTTP(S) Load Balancer with the External TCP/UDP Network Load Balancer, mistakenly thinking that any load balancer with an external IP can handle HTTP traffic, but the Network Load Balancer lacks Layer 7 features and is not optimized for HTTP workloads.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

External HTTP(S) Load Balancer

The External HTTP(S) Load Balancer is a regional or global, proxy-based Layer 7 load balancer that provides a single external IP address for distributing incoming HTTP traffic across Compute Engine instances in a managed instance group. It supports HTTP and HTTPS protocols, health checks, and autoscaling, making it ideal for web applications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Internal TCP/UDP Load Balancer

    Why it's wrong here

    This regional load balancer operates at Layer 4 and only supports traffic from clients that are inside the same VPC and region. It does not get an external IP address, so internet clients cannot reach the web application through it. Since the use case requires exposing the app to external users, this option is incorrect.

  • ✗

    External TCP/UDP Network Load Balancer

    Why it's wrong here

    This proxy forwards raw TCP/UDP packets and does not inspect HTTP payloads, making it incapable of routing by URL path, hostname, or header. Although it has an external IP, it lacks Layer 7 features like SSL termination and cookie-based affinity that are essential for a web application. Therefore, it is not the right choice for HTTP-based web traffic.

  • ✗

    SSL Proxy Load Balancer

    Why it's wrong here

    This load balancer is intended for non-HTTP TCP protocols that need SSL offloading, such as database or proprietary traffic. It terminates TLS but then forwards decrypted TCP packets without understanding HTTP methods, URLs, or headers, so it cannot perform content-based routing. For a web application served over HTTP/HTTPS, an L7 HTTP(S) load balancer is required.

  • ✓

    External HTTP(S) Load Balancer

    Why this is correct

    This global Layer 7 load balancer is purpose-built for HTTP and HTTPS traffic, supporting URL path and host-based routing, SSL termination, and integration with Cloud CDN. It provides a single external anycast IP address to all clients and intelligently distributes requests to backend web servers. This meets the company's requirement to expose an external web application with a single IP.

About these practice questions

This ACE question is part of Courseiva's 775-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.