Courseiva
Google Cloud Security →mediumMultiple Select

Cloud Digital Leader Google Cloud Security Practice Question

A company wants to implement a zero-trust security model for accessing internal applications. Which TWO Google Cloud services should they use together? (Choose 2)

⚠ Common exam trap

Many candidates confuse identity management (Cloud Identity) or network security (Cloud Armor, Cloud VPN) with zero-trust access services; candidates might pick Cloud Identity because it sounds related to identity, but it lacks the access enforcement capabilities of IAP and BeyondCorp Enterprise.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identity-Aware Proxy (IAP)

Identity-Aware Proxy (IAP) is correct because it enforces zero-trust access to internal applications by verifying a user's identity and context (via Google identity and IAM) before allowing requests to reach the app, rather than relying on network location. BeyondCorp Enterprise is correct because it provides the zero-trust access framework—context-aware access policies, device trust, and continuous authorization—that works with IAP to protect internal apps without a VPN. Together, BeyondCorp Enterprise supplies the policy/context engine and IAP enforces those policies at the application layer, which is exactly the zero-trust pattern for internal app access. Cloud Identity is not the right pairing here because it is primarily an identity and device management service (IdP/endpoint management), not the access-enforcement or context-aware policy layer for internal apps. Cloud Armor is a WAF/DDoS protection service for external HTTP(S) load balancers, and Cloud VPN provides network-level connectivity, both of which rely on perimeter/network trust rather than zero-trust application access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cloud Identity

    Why it's wrong here

    Cloud Identity is a directory and identity management service that provides user login, SSO, and device management, but it does not enforce access decisions on individual resources. Zero trust requires context-aware, per-request authorization at the resource layer, which Cloud Identity alone cannot provide. It is a foundational component, not the access-control mechanism.

  • ✗

    Cloud Armor

    Why it's wrong here

    Cloud Armor is a network security service that provides DDoS protection and a web application firewall (WAF) at the edge. It filters traffic based on IP, geo, and Layer 7 signatures, but it does not inspect the user's identity, device posture, or session context. Therefore, it cannot enforce the identity-centric, dynamic zero-trust policies required for granular access control.

  • ✓

    Identity-Aware Proxy (IAP)

    Why this is correct

    Identity-Aware Proxy (IAP) enforces zero-trust access by intercepting requests to applications and verifying the user's identity and contextual attributes, such as device security and network origin, against Cloud IAM policies. It applies least-privilege principles at the application layer, allowing only authenticated and authorized users to reach resources. IAP is a key building block for zero trust because it turns access decisions from network-based to identity-based.

  • ✓

    BeyondCorp Enterprise

    Why this is correct

    BeyondCorp Enterprise is Google Cloud's comprehensive zero-trust platform, which operationalizes the BeyondCorp framework by combining IAP with endpoint threat detection, data loss prevention, and continuous risk analysis. It goes beyond per-application controls to provide unified, adaptive access policies across the enterprise, incorporating real-time signals from user behavior and device health. This makes it the complete solution for implementing zero trust across hybrid and multi-cloud environments.

  • ✗

    Cloud VPN

    Why it's wrong here

    Cloud VPN creates encrypted IPsec tunnels to connect on-premises networks to Google Cloud, providing secure connectivity at the network layer. However, once a connection is established, it typically grants broad network access without verifying the identity or context of each individual user or request. This aligns with the traditional perimeter-based model, not zero trust, which demands per-request verification and context-aware authorization.

About these practice questions

One of 848 original GCDL practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.