Courseiva

Google PCA Manage and provision cloud infrastructure Practice Question

A company is deploying a web application on Compute Engine behind a global HTTP(S) load balancer. They want to restrict access to only traffic from specific IP ranges. Which load balancer feature should they use?

⚠ Common exam trap

Watch out — candidates often confuse VPC firewall rules with Cloud Armor, assuming that firewall rules can filter on the original client IP behind a load balancer, but in reality, VPC firewall rules only see the load balancer's proxy IPs, making Cloud Armor the only viable option for IP-based access control at the edge.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cloud Armor security policies.

Cloud Armor security policies are the correct choice because they allow you to define IP-based allow/deny rules at the edge of Google's network, directly integrated with the global HTTP(S) load balancer. This provides granular access control based on source IP ranges before traffic reaches your backend instances, which is exactly what the requirement specifies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Cloud Armor security policies.

    Why this is correct

    Cloud Armor security policies attach directly to the global HTTP(S) load balancer's backend service, letting you define allow or deny rules matching source IP ranges. This satisfies the requirement to restrict access to specific IP ranges at the edge, before traffic reaches Compute Engine instances.

  • ✗

    VPC firewall rules.

    Why it's wrong here

    VPC firewall rules filter traffic at the instance network interface, so they cannot evaluate the load balancer's client IP or apply at the global forwarding layer. Firewall rules would be correct for controlling traffic to VMs directly, not for restricting access through a global HTTP(S) load balancer.

  • ✗

    Identity-Aware Proxy (IAP).

    Why it's wrong here

    Identity-Aware Proxy authenticates users and enforces identity-based access to backends, not source IP range filtering. IAP would be the correct feature when access must be gated on user identity or Google account context rather than on client network addresses.

  • ✗

    Cloud CDN.

    Why it's wrong here

    Cloud CDN caches content at edge locations to reduce latency and origin load; it does not evaluate client source addresses for allow-listing. Cloud CDN would be the right feature when the goal is accelerating static or cacheable responses, not restricting traffic by IP range.

About these practice questions

Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.