Cloud Digital Leader Trust and security with Google Cloud Practice Question
A company has employees who use personal (unmanaged) devices to access corporate applications. The security team wants to prevent sensitive Google Workspace documents from being downloaded to personal devices. Which Google control most directly addresses this data loss prevention requirement for device-based scenarios?
⚠ Common exam trap
Many candidates confuse network-level controls (like Cloud Armor) or authentication controls (like 2FA) with device-level data loss prevention, failing to recognize that only context-aware access with endpoint management can enforce granular action restrictions based on device trust status.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Google Workspace context-aware access and endpoint management controls that restrict actions (such as downloads) for users accessing from unmanaged personal devices
Google Workspace context-aware access combined with endpoint management allows administrators to create access level policies that restrict specific actions—such as downloading, printing, or copying—based on device trust signals. When a user accesses Google Workspace from an unmanaged personal device, the policy can block the download of sensitive documents directly, addressing the data loss prevention requirement at the action level rather than just the access level.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cloud Armor, by blocking requests from IP addresses associated with personal devices
Why it's wrong here
Cloud Armor protects applications that sit behind Google Cloud external HTTP(S) load balancers by filtering traffic based on network-layer signals like IPv4/IPv6 ranges, geolocation, and HTTP headers. It cannot inspect whether the client device is enrolled in an endpoint management system or whether it has a verified device certificate because those attributes are not exposed in the network packet. Moreover, personal devices often have dynamic IP addresses or share a NAT address, making IP-based blocking either ineffective or overly broad, and Google Drive itself is not a customer-managed HTTP(S) load-balanced service that Cloud Armor can guard.
- ✓
Google Workspace context-aware access and endpoint management controls that restrict actions (such as downloads) for users accessing from unmanaged personal devices
Why this is correct
Google Workspace provides device-level context-aware access. Organizations can define policies that restrict capabilities based on device enrollment status — allowing read-only web access on unmanaged devices while blocking downloads, or requiring device enrollment to access sensitive content.
- ✗
Enabling two-factor authentication for all users, which prevents unauthorized access
Why it's wrong here
Two-factor authentication (2FA) verifies the user's identity through a second factor (e.g., TOTP or FIDO2 security key), but it does not inspect the endpoint's enrollment status or risk profile. After a successful 2FA challenge, the authenticated session on an unmanaged personal device retains the same Google Drive permissions as on a company-managed device, so the user can still download files. Google Workspace context-aware access would be needed to evaluate device attributes such as device compliance or certificate presence, which 2FA alone cannot provide.
- ✗
Encrypting all Google Drive files so they cannot be read on personal devices
Why it's wrong here
Google Drive files are encrypted at rest by Google, but this encryption is transparent to authorized users. An authenticated user can still download and read files on a personal device — encryption doesn't prevent downloads.
Go deeper
Related to this question
Learn chapter
Benefits of Google Cloud
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Data Loss Prevention
Data Loss Prevention (DLP) is a set of tools and processes that help organizations stop sensitive information from being shared, leaked, or stolen, whether accidentally or on purpose.
About these practice questions
This GCDL question is part of Courseiva's 829-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.