Google PCA Designing for Security and Compliance Practice Question
A company runs a public-facing web application on Compute Engine instances behind an external HTTP(S) load balancer. They want to protect the application from common web attacks such as SQL injection and cross-site scripting, and they also want to restrict access to known IP ranges. Which Google Cloud service should they use?
⚠ Common exam trap
It's easy for candidates to confuse network-layer firewall rules with application-layer WAF, or assuming IAP provides WAF protection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud Armor security policy with preconfigured WAF rules and IP allowlist rules.
Cloud Armor is the correct choice because it provides both WAF protection against common web attacks and IP-based access control. It is designed to work with external HTTP(S) load balancers, making it the appropriate service for securing a public web application. The other options either lack WAF capabilities or are intended for different use cases such as performance or identity-based access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
VPC firewall rules to allow only specific IP ranges and block malicious traffic.
Why it's wrong here
VPC firewall rules operate at the network layer (Layer 3/4) and cannot inspect HTTP traffic for SQL injection or XSS. They can restrict IP ranges but do not provide WAF capabilities. While firewall rules are necessary for network security, they are insufficient for protecting against application-layer attacks. The question specifically requires web attack protection, which firewall rules cannot provide.
- ✗
Cloud CDN with signed URLs to restrict access and cache content.
Why it's wrong here
Cloud CDN improves performance and can restrict access via signed URLs, but it does not inspect or block malicious payloads like SQL injection or XSS. Signed URLs are for controlling access to cached content, not for WAF. This option does not address the requirement to protect against common web attacks. It is a performance and access control tool, not a security inspection service.
- ✓
Cloud Armor security policy with preconfigured WAF rules and IP allowlist rules.
Why this is correct
Cloud Armor provides WAF capabilities with preconfigured rules for OWASP Top 10 threats like SQL injection and XSS, and it supports IP allowlist/denylist rules. It integrates with external HTTP(S) load balancers to filter traffic at the edge. This directly meets both requirements: protecting against web attacks and restricting access by IP. It is the native Google Cloud solution for this scenario.
- ✗
Identity-Aware Proxy (IAP) to authenticate users and enforce access policies.
Why it's wrong here
IAP controls access to applications based on user identity and context, but it does not inspect HTTP traffic for web vulnerabilities like SQL injection or XSS. It is designed for zero-trust access to internal apps, not for protecting public-facing web apps from attacks. While it can restrict access, it does not provide WAF functionality, so it does not meet the requirement.
Go deeper
Related to this question
Learn chapter
Google Cloud Compute Options Overview
Key term
Service
A service is a software component or system that performs a specific function and is available to be used by other programs or users over a network.
Key term
WAF
A Web Application Firewall (WAF) is a security tool that filters, monitors, and blocks HTTP traffic to and from a web application to protect it from common attacks.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.