hardMultiple Choice
Google ACE Practice Question: Configuring Identity-Aware Proxy (IAP) for a web…
You are configuring Identity-Aware Proxy (IAP) for a web application running on Compute Engine. Users authenticate through IAP and are granted access based on their email addresses. However, some users report that they are prompted to sign in multiple times during the same session. What is the most likely cause?
⚠ Common exam trap
Watch out — candidates often confuse session timeout with idle timeout or assume the issue is related to backend cookie handling, but Google specifically tests the understanding that IAP's configurable session TTL directly controls re-authentication frequency.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The IAP session timeout is set too low.
The IAP session timeout determines how long a user's authenticated session remains valid before requiring re-authentication. If this timeout is set too low, users will be prompted to sign in multiple times during a single session, even if they are actively using the application. The default IAP session timeout is 1 hour, but it can be configured up to 24 hours; a low value directly causes repeated login prompts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The backend service is missing the IAP session cookie validation.
Why it's wrong here
IAP itself validates and manages its own session cookie; the backend service never performs this validation, so a missing check there cannot cause re-prompting. Backend cookie validation is relevant only for custom authentication outside IAP. Repeated prompts instead indicate the IAP OAuth client or cookie settings are misconfigured.
- ✗
The users are accessing the application via different browsers.
Why it's wrong here
IAP sessions are tied to the Google account cookie in each browser, so signing in through separate browsers creates independent sessions and repeated prompts; the cause is session cookie scope, not browser choice itself. It is tempting because browser differences can affect cookie handling, but the correct fix is consistent browser use or a shared identity session.
- ✗
The backend service does not support HTTPS.
Why it's wrong here
IAP terminates TLS at the load balancer and requires HTTPS on the backend service, but a non-HTTPS backend produces 502 errors rather than repeated sign-in prompts. Repeated authentication stems from cookie or session configuration, not transport encryption. HTTPS backends are required when IAP must forward authenticated requests to Compute Engine instances.
- ✓
The IAP session timeout is set too low.
Why this is correct
A low IAP session timeout forces re-authentication once the session cookie expires, so users signing in repeatedly during one working session hit that limit. Raising the timeout to match the expected session duration satisfies the stem's requirement for continuous access, since IAP issues its own session cookie independent of the underlying Google identity.
Go deeper
Related to this question
About these practice questions
Courseiva writes every ACE question from scratch — 775 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.