Cloud Digital Leader Google Cloud Security Practice Question
A company wants to implement a zero-trust security model for accessing internal applications. Which TWO Google Cloud services should they use together? (Choose 2)
⚠ Common exam trap
Many candidates confuse identity management (Cloud Identity) or network security (Cloud Armor, Cloud VPN) with zero-trust access services; candidates might pick Cloud Identity because it sounds related to identity, but it lacks the access enforcement capabilities of IAP and BeyondCorp Enterprise.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identity-Aware Proxy (IAP)
Identity-Aware Proxy (IAP) is correct because it enforces zero-trust access to internal applications by verifying a user's identity and context (via Google identity and IAM) before allowing requests to reach the app, rather than relying on network location. BeyondCorp Enterprise is correct because it provides the zero-trust access framework—context-aware access policies, device trust, and continuous authorization—that works with IAP to protect internal apps without a VPN. Together, BeyondCorp Enterprise supplies the policy/context engine and IAP enforces those policies at the application layer, which is exactly the zero-trust pattern for internal app access. Cloud Identity is not the right pairing here because it is primarily an identity and device management service (IdP/endpoint management), not the access-enforcement or context-aware policy layer for internal apps. Cloud Armor is a WAF/DDoS protection service for external HTTP(S) load balancers, and Cloud VPN provides network-level connectivity, both of which rely on perimeter/network trust rather than zero-trust application access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cloud Identity
Why it's wrong here
Cloud Identity is a directory and identity management service that provides user login, SSO, and device management, but it does not enforce access decisions on individual resources. Zero trust requires context-aware, per-request authorization at the resource layer, which Cloud Identity alone cannot provide. It is a foundational component, not the access-control mechanism.
- ✗
Cloud Armor
Why it's wrong here
Cloud Armor is a network security service that provides DDoS protection and a web application firewall (WAF) at the edge. It filters traffic based on IP, geo, and Layer 7 signatures, but it does not inspect the user's identity, device posture, or session context. Therefore, it cannot enforce the identity-centric, dynamic zero-trust policies required for granular access control.
- ✓
Identity-Aware Proxy (IAP)
Why this is correct
Identity-Aware Proxy (IAP) enforces zero-trust access by intercepting requests to applications and verifying the user's identity and contextual attributes, such as device security and network origin, against Cloud IAM policies. It applies least-privilege principles at the application layer, allowing only authenticated and authorized users to reach resources. IAP is a key building block for zero trust because it turns access decisions from network-based to identity-based.
- ✓
BeyondCorp Enterprise
Why this is correct
BeyondCorp Enterprise is Google Cloud's comprehensive zero-trust platform, which operationalizes the BeyondCorp framework by combining IAP with endpoint threat detection, data loss prevention, and continuous risk analysis. It goes beyond per-application controls to provide unified, adaptive access policies across the enterprise, incorporating real-time signals from user behavior and device health. This makes it the complete solution for implementing zero trust across hybrid and multi-cloud environments.
- ✗
Cloud VPN
Why it's wrong here
Cloud VPN creates encrypted IPsec tunnels to connect on-premises networks to Google Cloud, providing secure connectivity at the network layer. However, once a connection is established, it typically grants broad network access without verifying the identity or context of each individual user or request. This aligns with the traditional perimeter-based model, not zero trust, which demands per-request verification and context-aware authorization.
Go deeper
Related to this question
Learn chapter
Google Cloud Privacy and Trust Principles
Key term
VPN
A VPN creates an encrypted tunnel over a public network to securely connect remote users or sites to a private network.
Key term
Security model
A security model is a formal framework that defines how subjects (users, processes) can access objects (files, resources) based on rules, ensuring confidentiality, integrity, and availability.
About these practice questions
One of 848 original GCDL practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.