Courseiva
Google Cloud SecuritymediumMultiple ChoiceObjective-mapped

Cloud Digital Leader Google Cloud Security Practice Question

A company wants to replace its VPN-based remote access with a zero-trust solution that verifies user identity and device health before granting access to internal applications. Which Google Cloud service should they use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

BeyondCorp Enterprise

BeyondCorp Enterprise provides zero-trust access based on user identity and device context, eliminating the need for a VPN. IAP is a component but the full solution is BeyondCorp Enterprise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • BeyondCorp Enterprise

    Why this is correct

    BeyondCorp Enterprise is Google Cloud's complete zero-trust access solution, designed to replace a traditional VPN. It enforces access decisions based on user identity, device security posture, and context, rather than granting broad network-level entry. By combining Identity-Aware Proxy, endpoint verification, and adaptive policies into a single platform, it protects applications without exposing the entire network, which is why it is the correct replacement for VPN-based remote access.

  • Identity-Aware Proxy (IAP)

    Why it's wrong here

    Identity-Aware Proxy (IAP) is a single component within the BeyondCorp Enterprise architecture, not a standalone VPN replacement. IAP provides per-request application-level authorization using identity and context, but it does not include the broader zero-trust capabilities such as endpoint health verification, data loss prevention, or threat detection. Choosing IAP alone leaves gaps in endpoint security and policy enforcement, so it is incomplete for replacing an enterprise VPN.

  • Cloud VPN

    Why it's wrong here

    Cloud VPN creates an IPSec tunnel between on-premises networks and Google Cloud, giving users or sites network-level access to the entire private CIDR range. This follows the legacy perimeter-security model: once inside the tunnel, a user retains broad network trust, regardless of identity, device, or context. It lacks granular, per-request authorization and does not enforce zero-trust principles, making it the opposite of a zero-trust remote-access solution.

  • Cloud Identity

    Why it's wrong here

    Cloud Identity is an identity and access management service that provides user lifecycle management, SSO, and group-based policies for Google Cloud and third-party apps. It does not mediate access to resources or evaluate device context and security posture for every request. While identity is a key input to zero trust, Cloud Identity alone cannot replace a VPN because it lacks the proxy and enforcement layer needed to control application-level access.

About these practice questions

Courseiva writes every GCDL question from scratch — 829 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.