Courseiva

Google PCA Manage implementation of cloud architecture Practice Question

A company is deploying a global web application on Google Cloud. The application serves static content from a Cloud Storage bucket and dynamic content from a managed instance group backend. They want to use a single global IP address and provide low latency to users worldwide. They also want to protect the application from DDoS attacks. Which solution should they implement?

⚠ Common exam trap

The trap here is assuming that a TCP proxy load balancer can serve HTTP(S) traffic and integrate with Cloud CDN; it operates at layer 4 and lacks these features.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure an external HTTP(S) load balancer with a global anycast IP address, a backend service for the managed instance group, and a backend bucket for the Cloud Storage bucket. Enable Cloud CDN and Google Cloud Armor.

The external HTTP(S) load balancer provides a global anycast IP and supports both backend services and backend buckets, allowing static and dynamic content to be served from the same IP. Cloud CDN caches static content for low latency, and Cloud Armor protects against DDoS and other attacks. This integrated solution meets all the requirements without third-party dependencies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure an external HTTP(S) load balancer with a global anycast IP address, a backend service for the managed instance group, and a backend bucket for the Cloud Storage bucket. Enable Cloud CDN and Google Cloud Armor.

    Why this is correct

    An external HTTP(S) load balancer provides a single global anycast IP address and can route traffic to both a managed instance group backend and a Cloud Storage backend bucket. Cloud CDN caches static content at the edge for low latency, and Cloud Armor provides DDoS protection and WAF capabilities. This meets all requirements.

  • ✗

    Use a global external HTTP(S) load balancer with a single backend service that points to both the managed instance group and the Cloud Storage bucket using a hybrid connectivity network endpoint group (NEG).

    Why it's wrong here

    A backend service can only point to one type of backend (e.g., instance groups or NEGs), not both a managed instance group and a Cloud Storage bucket. Cloud Storage buckets are configured as backend buckets, not as part of a backend service. This approach is not supported.

  • ✗

    Deploy a third-party DDoS protection service in front of the application, and use a network load balancer with a global IP address for both backends.

    Why it's wrong here

    A network load balancer (TCP/UDP) does not provide HTTP(S) features such as URL path routing or Cloud CDN integration. It also requires a third-party DDoS service, which adds complexity and cost. The external HTTP(S) load balancer with Cloud Armor provides integrated DDoS protection and meets the requirements more efficiently.

  • ✗

    Create a global TCP proxy load balancer with a global IP address, and configure backends for the managed instance group and Cloud Storage bucket.

    Why it's wrong here

    A TCP proxy load balancer operates at layer 4 and does not support HTTP(S) features like URL mapping to different backends or Cloud CDN integration. It cannot route based on URL paths to separate backends for static and dynamic content. It also does not provide DDoS protection via Cloud Armor. Thus it is not suitable.

About these practice questions

Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.