Google PCA Manage and provision cloud infrastructure Practice Question
A company is deploying a web application on Compute Engine behind a global HTTP(S) load balancer. They want to restrict access to only traffic from specific IP ranges. Which load balancer feature should they use?
⚠ Common exam trap
Watch out — candidates often confuse VPC firewall rules with Cloud Armor, assuming that firewall rules can filter on the original client IP behind a load balancer, but in reality, VPC firewall rules only see the load balancer's proxy IPs, making Cloud Armor the only viable option for IP-based access control at the edge.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud Armor security policies.
Cloud Armor security policies are the correct choice because they allow you to define IP-based allow/deny rules at the edge of Google's network, directly integrated with the global HTTP(S) load balancer. This provides granular access control based on source IP ranges before traffic reaches your backend instances, which is exactly what the requirement specifies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Cloud Armor security policies.
Why this is correct
Cloud Armor security policies attach directly to the global HTTP(S) load balancer's backend service, letting you define allow or deny rules matching source IP ranges. This satisfies the requirement to restrict access to specific IP ranges at the edge, before traffic reaches Compute Engine instances.
- ✗
VPC firewall rules.
Why it's wrong here
VPC firewall rules filter traffic at the instance network interface, so they cannot evaluate the load balancer's client IP or apply at the global forwarding layer. Firewall rules would be correct for controlling traffic to VMs directly, not for restricting access through a global HTTP(S) load balancer.
- ✗
Identity-Aware Proxy (IAP).
Why it's wrong here
Identity-Aware Proxy authenticates users and enforces identity-based access to backends, not source IP range filtering. IAP would be the correct feature when access must be gated on user identity or Google account context rather than on client network addresses.
- ✗
Cloud CDN.
Why it's wrong here
Cloud CDN caches content at edge locations to reduce latency and origin load; it does not evaluate client source addresses for allow-listing. Cloud CDN would be the right feature when the goal is accelerating static or cacheable responses, not restricting traffic by IP range.
Go deeper
Related to this question
Learn chapter
Virtual Machine Instances in Compute Engine
Key term
Load balancer
A load balancer is a device or software that distributes incoming network traffic across multiple servers so no single server gets overwhelmed.
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
About these practice questions
Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.