Courseiva

Google PCA Design for security and compliance Practice Question

A company is deploying a web application on Compute Engine. They want to ensure that only authenticated users can access the application. Which Google Cloud service should they use?

⚠ Common exam trap

Many exam-takers confuse network-level services like Cloud Load Balancing or Cloud CDN with security controls, assuming they provide authentication simply because they sit in front of the application, but they lack any identity verification mechanism.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identity-Aware Proxy

Identity-Aware Proxy (IAP) is the correct choice because it enforces access control at the edge of Google's network, verifying user identity and context before allowing traffic to reach the Compute Engine instance. IAP uses OAuth 2.0 and signed headers to authenticate users, ensuring only authorized requests are forwarded to the backend, without requiring any changes to the application itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Identity-Aware Proxy

    Why this is correct

    Identity-Aware Proxy performs authentication and authorisation at the application layer before requests reach the Compute Engine backend, verifying user identity and context. This enforces that only authenticated users access the application, satisfying the stated access constraint without network-level controls.

  • ✗

    Cloud Load Balancing

    Why it's wrong here

    Cloud Load Balancing distributes incoming traffic across backends but does not itself authenticate users. It is tempting because it fronts the Compute Engine deployment and integrates with IAP, yet the load balancer only routes requests; Identity-Aware Proxy performs the actual authentication check.

  • ✗

    Cloud CDN

    Why it's wrong here

    Cloud CDN caches and serves content from edge locations, providing no authentication mechanism. It is tempting because it improves latency and reduces origin load for web applications, but identity verification requires Identity-Aware Proxy, which enforces user authentication before requests reach the Compute Engine backend.

  • ✗

    Cloud DNS

    Why it's wrong here

    Cloud DNS resolves domain names to IP addresses; it performs no user authentication. It is tempting because every web application needs DNS records to be reachable, but name resolution is unrelated to verifying identity, which Identity-Aware Proxy handles at the application layer.

About these practice questions

Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.