easyMultiple Choice
Google ACE Practice Question: A startup runs its application entirely on Cloud…
A startup runs its application entirely on Cloud Run. They want to use a custom domain (api.mycompany.com) instead of the default Cloud Run URL. Which GCP feature maps a custom domain to a Cloud Run service?
⚠ Common exam trap
Watch out — candidates often assume a simple DNS CNAME record is sufficient, but Cloud Run requires domain ownership verification and SSL certificate management, which only Domain Mappings or a Load Balancer with Serverless NEG provide.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud Run Domain Mappings or a Global Load Balancer with a Serverless NEG
Cloud Run Domain Mappings provide a native, managed way to map a custom domain to a Cloud Run service without additional infrastructure. Alternatively, a Global Load Balancer with a Serverless NEG (Network Endpoint Group) can also route traffic from a custom domain to Cloud Run, offering advanced features like SSL termination and traffic splitting. Both approaches are officially supported by Google Cloud for custom domain mapping.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cloud DNS — create a CNAME record pointing to the Cloud Run URL
Why it's wrong here
Creating a CNAME record in Cloud DNS that points to the default Cloud Run URL is insufficient because Cloud Run issues TLS certificates only for endpoints it recognizes via Domain Mappings. When a request arrives with your custom Host header, the run.app frontend will not route it to the service, resulting in TLS or 404 errors. You must first create a Domain Mapping so Cloud Run can verify ownership and provision a certificate for your domain; the CNAME alone is not the missing piece.
- ✓
Cloud Run Domain Mappings or a Global Load Balancer with a Serverless NEG
Why this is correct
Cloud Run Domain Mappings and a Global Load Balancer with a Serverless NEG are both valid, production-ready approaches. Domain Mappings offer the simplest path for a single service: you verify the domain, and Cloud Run automatically provisions a Google-managed TLS certificate. The load balancer approach is better when you need advanced routing, multi-region failover, or CDN/WAF features; a Serverless NEG allows the global external Application Load Balancer to direct traffic to your Cloud Run service. Choose based on whether you need basic custom-domain support or full-fledged edge routing.
- ✗
Cloud Endpoints with an API gateway configuration
Why it's wrong here
Cloud Endpoints is an API management system based on Service Control/Service Management; it provides authentication, quotas, and monitoring, but its ESPv2 proxy does not map custom domains to Cloud Run. Even if you deploy Endpoints in front of a Cloud Run service, you still need a separate mechanism—like Domain Mapping or a load balancer—to make the custom domain reach the gateway. Thus, it adds significant configuration overhead and is not the standard solution for simply exposing a service on a custom domain.
- ✗
Firebase Hosting rewrites to Cloud Run
Why it's wrong here
Firebase Hosting's rewrite feature can proxy requests to a Cloud Run service, which works for sites already hosted on Firebase, but it forces you to add and maintain a Firebase project, an extra layer of indirection, and an additional hit on the request path. It is not a native Cloud Run solution. Cloud Run's own Domain Mapping handles custom domains directly with automatic TLS, while the load balancer option adds global capabilities without requiring a Firebase dependency. Use Firebase Hosting rewrites only if you are already committed to Firebase and need to serve static content alongside your serverless workload.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
Learn chapter
Network Intelligence Center
Key term
Service
A service is a software component or system that performs a specific function and is available to be used by other programs or users over a network.
Key term
Route
A route is a path that data takes through a network from one device or network to another, determined by routing protocols and configured rules.
About these practice questions
One of 775 original ACE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.