Courseiva
Trust and security with Google CloudmediumMultiple ChoiceObjective-mapped

Cloud Digital Leader Trust and security with Google Cloud Practice Question

A company has employees who use personal (unmanaged) devices to access corporate applications. The security team wants to prevent sensitive Google Workspace documents from being downloaded to personal devices. Which Google control most directly addresses this data loss prevention requirement for device-based scenarios?

⚠ Common exam trap

Many candidates confuse network-level controls (like Cloud Armor) or authentication controls (like 2FA) with device-level data loss prevention, failing to recognize that only context-aware access with endpoint management can enforce granular action restrictions based on device trust status.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Google Workspace context-aware access and endpoint management controls that restrict actions (such as downloads) for users accessing from unmanaged personal devices

Google Workspace context-aware access combined with endpoint management allows administrators to create access level policies that restrict specific actions—such as downloading, printing, or copying—based on device trust signals. When a user accesses Google Workspace from an unmanaged personal device, the policy can block the download of sensitive documents directly, addressing the data loss prevention requirement at the action level rather than just the access level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Cloud Armor, by blocking requests from IP addresses associated with personal devices

    Why it's wrong here

    Cloud Armor protects applications that sit behind Google Cloud external HTTP(S) load balancers by filtering traffic based on network-layer signals like IPv4/IPv6 ranges, geolocation, and HTTP headers. It cannot inspect whether the client device is enrolled in an endpoint management system or whether it has a verified device certificate because those attributes are not exposed in the network packet. Moreover, personal devices often have dynamic IP addresses or share a NAT address, making IP-based blocking either ineffective or overly broad, and Google Drive itself is not a customer-managed HTTP(S) load-balanced service that Cloud Armor can guard.

  • Google Workspace context-aware access and endpoint management controls that restrict actions (such as downloads) for users accessing from unmanaged personal devices

    Why this is correct

    Google Workspace provides device-level context-aware access. Organizations can define policies that restrict capabilities based on device enrollment status — allowing read-only web access on unmanaged devices while blocking downloads, or requiring device enrollment to access sensitive content.

  • Enabling two-factor authentication for all users, which prevents unauthorized access

    Why it's wrong here

    Two-factor authentication (2FA) verifies the user's identity through a second factor (e.g., TOTP or FIDO2 security key), but it does not inspect the endpoint's enrollment status or risk profile. After a successful 2FA challenge, the authenticated session on an unmanaged personal device retains the same Google Drive permissions as on a company-managed device, so the user can still download files. Google Workspace context-aware access would be needed to evaluate device attributes such as device compliance or certificate presence, which 2FA alone cannot provide.

  • Encrypting all Google Drive files so they cannot be read on personal devices

    Why it's wrong here

    Google Drive files are encrypted at rest by Google, but this encryption is transparent to authorized users. An authenticated user can still download and read files on a personal device — encryption doesn't prevent downloads.

About these practice questions

This GCDL question is part of Courseiva's 829-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.