Google PCA Manage and provision cloud infrastructure Practice Question
A company is migrating a monolithic application to microservices on Google Cloud. They need to manage service-to-service authentication and authorization. Which service should they use?
⚠ Common exam trap
A common mix-up: candidates confuse Cloud Endpoints (API management for external clients) with the internal service-to-service security needs of microservices, or assume Cloud IAP can be extended to internal traffic, but IAP only works for user-facing HTTP(S) requests and cannot enforce policies between backend services.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Service Mesh (Anthos)
Service Mesh (Anthos) provides a dedicated infrastructure layer for managing service-to-service communication, including mutual TLS (mTLS) authentication, fine-grained authorization policies, and observability. It uses sidecar proxies (Envoy) to intercept traffic and enforce security policies without modifying application code, making it ideal for microservices authentication and authorization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cloud NAT
Why it's wrong here
Cloud NAT provides outbound internet address translation for private instances; it performs no authentication or authorisation between services. It is tempting because it handles private-network egress, which is correct when services need outbound internet access without public IPs, not for verifying caller identity.
- ✗
Cloud Identity-Aware Proxy
Why it's wrong here
Identity-Aware Proxy authenticates user-to-application access at the load balancer, not service-to-service calls between microservices. It is tempting because it enforces identity-based access, which is correct when protecting internal web apps from external users rather than for workload identity between backend services.
- ✗
Cloud Endpoints
Why it's wrong here
Cloud Endpoints manages and secures APIs exposed to consumers, adding authentication at the API gateway layer, but it does not broker identity between internal microservices. It is tempting for publishing and monitoring REST APIs, which is correct when external clients call your API rather than for service-to-service auth.
- ✓
Service Mesh (Anthos)
Why this is correct
Anthos Service Mesh issues mutual TLS identities to each workload, so service-to-service authentication and authorisation are enforced without application code changes. This satisfies the microservices requirement for cryptographic workload identity and policy-based access control across the mesh.
Go deeper
Related to this question
Learn chapter
Deployment Manager and Infrastructure as Code
Key term
Service
A service is a software component or system that performs a specific function and is available to be used by other programs or users over a network.
Key term
Anthos
Anthos is a Google Cloud platform that lets you run applications consistently across different computing environments, like on-premises data centers and multiple public clouds.
About these practice questions
Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.