Cloud Digital Leader Trust and security with Google Cloud Practice Question
A retail company runs a customer-facing web application on Compute Engine instances behind an external Application Load Balancer. The security team wants to protect the application from common web attacks such as SQL injection and cross-site scripting, and also wants to restrict access to only known good IP addresses. They need a managed solution that integrates with the load balancer and requires minimal operational overhead. Which Google Cloud service should they use?
⚠ Common exam trap
Test-takers frequently confuse identity-based access control (IAP) with network-level web application protection, assuming that any security service can block web attacks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud Armor
Cloud Armor is the correct choice because it is a managed WAF and DDoS protection service that integrates with external Application Load Balancers. It provides preconfigured rules to block common web attacks like SQL injection and XSS, and allows IP allowlisting/denylisting through security policies. This aligns with the need for a low-overhead, integrated security solution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cloud Identity-Aware Proxy (IAP)
Why it's wrong here
IAP controls access to applications based on user identity and context, not on network-level IP restrictions or web attack signatures. It is designed for internal applications or user authentication, not for public-facing WAF protection. Using IAP would not block SQL injection or XSS attacks, and it does not integrate with load balancers for WAF purposes.
- ✗
Cloud VPN
Why it's wrong here
Cloud VPN provides encrypted connectivity between on-premises networks and Google Cloud VPCs. It does not inspect HTTP traffic for web attacks or provide IP-based access control for external users. It is a network connectivity service, not a security service for protecting web applications from common exploits.
- ✗
VPC Service Controls
Why it's wrong here
VPC Service Controls define security perimeters around Google Cloud services to mitigate data exfiltration risks. They do not inspect incoming web traffic for SQL injection or XSS, nor do they provide IP allowlisting for external users. They are used to restrict access to APIs and services within a perimeter, not to protect public web applications.
- ✓
Cloud Armor
Why this is correct
Cloud Armor is a managed web application firewall (WAF) and DDoS protection service that integrates directly with external Application Load Balancers. It provides preconfigured WAF rules for OWASP Top 10 threats like SQL injection and XSS, and supports IP allowlists/denylists via security policies. This meets the requirement for a managed solution with minimal overhead.
Go deeper
Related to this question
Learn chapter
Data Security: Encryption and Access Controls
Key term
Cross-site scripting
Cross-site scripting (XSS) is a security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users, often to steal data or hijack sessions.
Key term
Load balancer
A load balancer is a device or software that distributes incoming network traffic across multiple servers so no single server gets overwhelmed.
About these practice questions
One of 848 original GCDL practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.