Courseiva

Google PCA Manage and provision cloud infrastructure Practice Question

A company is migrating a monolithic application to microservices on Google Cloud. They need to manage service-to-service authentication and authorization. Which service should they use?

⚠ Common exam trap

A common mix-up: candidates confuse Cloud Endpoints (API management for external clients) with the internal service-to-service security needs of microservices, or assume Cloud IAP can be extended to internal traffic, but IAP only works for user-facing HTTP(S) requests and cannot enforce policies between backend services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Service Mesh (Anthos)

Service Mesh (Anthos) provides a dedicated infrastructure layer for managing service-to-service communication, including mutual TLS (mTLS) authentication, fine-grained authorization policies, and observability. It uses sidecar proxies (Envoy) to intercept traffic and enforce security policies without modifying application code, making it ideal for microservices authentication and authorization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cloud NAT

    Why it's wrong here

    Cloud NAT provides outbound internet address translation for private instances; it performs no authentication or authorisation between services. It is tempting because it handles private-network egress, which is correct when services need outbound internet access without public IPs, not for verifying caller identity.

  • ✗

    Cloud Identity-Aware Proxy

    Why it's wrong here

    Identity-Aware Proxy authenticates user-to-application access at the load balancer, not service-to-service calls between microservices. It is tempting because it enforces identity-based access, which is correct when protecting internal web apps from external users rather than for workload identity between backend services.

  • ✗

    Cloud Endpoints

    Why it's wrong here

    Cloud Endpoints manages and secures APIs exposed to consumers, adding authentication at the API gateway layer, but it does not broker identity between internal microservices. It is tempting for publishing and monitoring REST APIs, which is correct when external clients call your API rather than for service-to-service auth.

  • ✓

    Service Mesh (Anthos)

    Why this is correct

    Anthos Service Mesh issues mutual TLS identities to each workload, so service-to-service authentication and authorisation are enforced without application code changes. This satisfies the microservices requirement for cryptographic workload identity and policy-based access control across the mesh.

About these practice questions

Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.