Google PCA Manage and provision cloud infrastructure Practice Question
A company deploys a web application on Compute Engine behind a Global HTTPS Load Balancer. They need to restrict access to the application based on the client's IP address. Which Google Cloud service should they use?
⚠ Common exam trap
A common mix-up: candidates confuse VPC firewall rules with edge security, not realizing that VPC firewall rules cannot see the original client IP when a Global Load Balancer is in front, making Cloud Armor the only option for IP-based access control at the load balancer level.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud Armor
Cloud Armor is the correct choice because it provides IP-based access control at the edge of Google's network, integrated directly with the Global HTTPS Load Balancer. It allows you to create security policies with IP allow/deny rules that are evaluated before traffic reaches your Compute Engine instances, making it the appropriate service for client IP restriction at the load balancer level.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
VPC firewall rules
Why it's wrong here
VPC firewall rules filter traffic by source IP, but they act at the instance or subnet level, not on a Global HTTPS Load Balancer whose frontend IP is external. They are tempting because they do enforce IP-based filtering for Compute Engine workloads. Cloud Armor security policies are required to restrict access at the load balancer.
- ✗
Identity-Aware Proxy (IAP)
Why it's wrong here
Identity-Aware Proxy authenticates users and enforces identity-based access, not client IP filtering. IP-based restrictions on a Global HTTPS Load Balancer are configured through Cloud Armor security policies. IAP is tempting because it controls access, but it evaluates user identity and context rather than source IP addresses.
- ✓
Cloud Armor
Why this is correct
Cloud Armor attaches security policies to the Global HTTPS Load Balancer's backend service, filtering requests by source IP address at the edge. This satisfies the client-IP restriction requirement, which VPC firewall rules cannot enforce for external clients.
- ✗
Cloud CDN
Why it's wrong here
Cloud CDN caches HTTP responses at edge points of presence; it cannot evaluate client IP addresses to permit or deny requests. It is tempting because CDN edge nodes do see client IPs, but their purpose is content caching and acceleration, not access control. IP-based allow/deny belongs to Cloud Armor security policies attached to the load balancer's backend service.
Go deeper
Related to this question
Learn chapter
Load Balancing and Autoscaling
Key term
Service
A service is a software component or system that performs a specific function and is available to be used by other programs or users over a network.
Key term
Cloud Armor
Cloud Armor is a Google Cloud web application firewall (WAF) service that protects applications and websites from attacks like DDoS and SQL injection using customizable security rules.
About these practice questions
This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.