Courseiva
Trust and security with Google CloudeasyMultiple ChoiceObjective-mapped

Cloud Digital Leader Trust and security with Google Cloud Practice Question

A company's security team wants to ensure that only approved corporate devices can access Google Cloud resources, regardless of whether the user has valid credentials. Which Google Cloud security capability enforces device-level access requirements?

⚠ Common exam trap

Test-takers frequently confuse IAP's role in user authentication with device-level enforcement, not realizing that IAP delegates device context checks to Access Context Manager via access levels.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Access Context Manager, which enforces device-level access requirements as part of context-aware access control policies

Access Context Manager is the correct choice because it allows security teams to define context-aware access policies that include device-level attributes such as device OS type, device ID, and whether the device is managed (e.g., via endpoint verification or third-party EMM). This enforces device-level access requirements even if the user has valid credentials, directly addressing the scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Cloud Armor, which filters incoming requests based on IP allowlists and denylists

    Why it's wrong here

    Cloud Armor operates at the network edge, evaluating HTTP(S) traffic against configurable rules such as IP allowlists/denylists, geo-location, and OWASP Top 10 signatures. It does not have visibility into endpoint posture—whether a device is managed, encrypted, or screen-locked—because it inspects request attributes, not device trust signals. Therefore, while it can block malicious volumetric attacks, it cannot enforce device-level access requirements.

  • Access Context Manager, which enforces device-level access requirements as part of context-aware access control policies

    Why this is correct

    Access Context Manager is precisely the service for this. It allows security teams to define access levels (policies) that include device attribute requirements — managed/enrolled devices, disk encryption, screen lock. These conditions must be met in addition to valid credentials for access to be granted.

  • Identity-Aware Proxy (IAP), which provides application-level authentication but without device checks

    Why it's wrong here

    Identity-Aware Proxy (IAP) authenticates a user via Google identity and OAuth scopes, acting as the gatekeeper for application access. However, out of the box, IAP does not evaluate device security attributes; it only confirms the caller is a valid Google account holder. To enforce device management status, security teams must couple IAP with Access Context Manager, meaning IAP alone cannot satisfy the 'managed devices only' condition.

  • VPC Service Controls, which restrict access to Google APIs based on network perimeter membership

    Why it's wrong here

    VPC Service Controls constructs security perimeters around Google Cloud resources, blocking requests to services from outside defined network boundaries. It restricts based on project, VPC, and IP ranges, not on the security characteristics of the end-user device. As a result, it can prevent data exfiltration but cannot determine whether a laptop is managed, disk-encrypted, or screen-locked.

About these practice questions

One of 829 original GCDL practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.