Courseiva

Google PCA Manage and provision cloud infrastructure Practice Question

A company deploys a web application on Compute Engine behind a Global HTTPS Load Balancer. They need to restrict access to the application based on the client's IP address. Which Google Cloud service should they use?

⚠ Common exam trap

A common mix-up: candidates confuse VPC firewall rules with edge security, not realizing that VPC firewall rules cannot see the original client IP when a Global Load Balancer is in front, making Cloud Armor the only option for IP-based access control at the load balancer level.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cloud Armor

Cloud Armor is the correct choice because it provides IP-based access control at the edge of Google's network, integrated directly with the Global HTTPS Load Balancer. It allows you to create security policies with IP allow/deny rules that are evaluated before traffic reaches your Compute Engine instances, making it the appropriate service for client IP restriction at the load balancer level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VPC firewall rules

    Why it's wrong here

    VPC firewall rules filter traffic by source IP, but they act at the instance or subnet level, not on a Global HTTPS Load Balancer whose frontend IP is external. They are tempting because they do enforce IP-based filtering for Compute Engine workloads. Cloud Armor security policies are required to restrict access at the load balancer.

  • ✗

    Identity-Aware Proxy (IAP)

    Why it's wrong here

    Identity-Aware Proxy authenticates users and enforces identity-based access, not client IP filtering. IP-based restrictions on a Global HTTPS Load Balancer are configured through Cloud Armor security policies. IAP is tempting because it controls access, but it evaluates user identity and context rather than source IP addresses.

  • ✓

    Cloud Armor

    Why this is correct

    Cloud Armor attaches security policies to the Global HTTPS Load Balancer's backend service, filtering requests by source IP address at the edge. This satisfies the client-IP restriction requirement, which VPC firewall rules cannot enforce for external clients.

  • ✗

    Cloud CDN

    Why it's wrong here

    Cloud CDN caches HTTP responses at edge points of presence; it cannot evaluate client IP addresses to permit or deny requests. It is tempting because CDN edge nodes do see client IPs, but their purpose is content caching and acceleration, not access control. IP-based allow/deny belongs to Cloud Armor security policies attached to the load balancer's backend service.

About these practice questions

This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.