Courseiva

Cloud Digital Leader Google Cloud Products and Services Practice Question

An engineer needs to distribute incoming HTTP traffic across multiple backend VM instances in different regions, with automatic failover and SSL termination. Which load balancing product should they use?

⚠ Common exam trap

Candidates often confuse adjacent networking services — candidates pick Cloud CDN or Cloud Armor because they sound like traffic services, but only Cloud Load Balancing actually distributes and terminates traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cloud Load Balancing

Cloud Load Balancing is Google Cloud's fully managed, software-defined load balancing service that supports global anycast IPs, cross-region backend distribution, automatic failover via health checks, and SSL/TLS termination at the load balancer. It handles HTTP(S) traffic across VM instances in multiple regions with a single global IP, which matches every requirement in the scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cloud CDN

    Why it's wrong here

    Cloud CDN is incorrect because it is a content delivery network that caches static and dynamic content at edge locations to reduce latency and accelerate delivery, not a traffic distribution service. While Cloud CDN can be attached to a load balancer to offload cached responses, it does not route incoming HTTP traffic across multiple backend instances or regions, nor does it perform health checks or connection draining. Its core function is caching, not load balancing.

  • ✓

    Cloud Load Balancing

    Why this is correct

    Cloud Load Balancing is the correct choice for distributing incoming HTTP traffic across backend instances or services. It provides global, anycast-based HTTP(S) load balancing with a single virtual IP, enabling traffic to be routed to the nearest healthy backend across regions. It also offers SSL/TLS offloading, autoscaling, health checks, and failover, making it the appropriate service for high-availability traffic distribution.

  • ✗

    Cloud NAT

    Why it's wrong here

    Cloud NAT is incorrect because it is designed to provide outbound internet connectivity to private VM instances that do not have external IP addresses. It performs source network address translation, allowing private instances to initiate outbound connections, but it cannot accept inbound HTTP traffic or route it to different backends. Therefore, it is not a load-balancing solution for incoming requests.

  • ✗

    Cloud Armor

    Why it's wrong here

    Cloud Armor is incorrect because it is a security service that provides DDoS protection and a web application firewall (WAF) to filter and block malicious traffic. It can be attached to an HTTP(S) load balancer to enforce security policies, but it does not distribute traffic across servers or manage backend capacity. Its role is to protect, not to route or balance load, so it is not a load balancer itself.

Go deeper

Related to this question

About these practice questions

Courseiva writes every GCDL question from scratch — 848 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.