mediumMultiple Select
Google PCA Practice Question: A company runs a web application on GKE and wants…
A company runs a web application on GKE and wants to expose it to the internet using a global HTTP(S) load balancer with Cloud CDN. Which TWO GCP resources are required to configure this setup? (Choose TWO.)
⚠ Common exam trap
Candidates often confuse a Kubernetes Service of type LoadBalancer (which creates a regional Layer 4 load balancer) with the need for a global HTTP(S) load balancer, failing to recognize that only an Ingress with the GCE controller can provide the global, Layer 7 load balancing required for Cloud CDN.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Kubernetes Ingress resource with a GCE ingress controller
Option A is correct because a Kubernetes Ingress resource managed by the GCE ingress controller is what triggers GKE to provision a global external HTTP(S) load balancer and wire it to the application's Service; the ingress annotations (e.g., kubernetes.io/ingress.class: gce) and BackendConfig enable Cloud CDN on the resulting backend. Option C is correct because the global HTTP(S) load balancer requires a backend service that defines the instance groups/NEGs and a health check to determine which backends are healthy and eligible to receive traffic. Option B is not needed because Cloud NAT provides outbound internet access for private instances, not inbound load balancing. Option D is not required because a ClusterIP Service is sufficient as the Ingress backend; a Service of type LoadBalancer would instead provision a separate network load balancer and is not how GCE Ingress exposes apps. Option E is not relevant because Cloud VPN provides encrypted connectivity between networks, not internet-facing HTTP(S) load balancing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Kubernetes Ingress resource with a GCE ingress controller
Why this is correct
A Kubernetes Ingress with the GCE ingress controller provisions the external HTTP(S) load balancer and wires GKE services to it. It satisfies the requirement to expose the application globally, and its annotations enable Cloud CDN on the resulting load balancer.
- ✗
Cloud NAT gateway
Why it's wrong here
Cloud NAT provides outbound internet access for private instances; it performs no inbound load balancing or caching. It is tempting because GKE nodes without external IPs need NAT for egress, but exposing the app globally requires a global forwarding rule and target HTTP(S) proxy with a backend service.
- ✓
Backend service with health check configuration
Why this is correct
The backend service defines how the load balancer distributes traffic to GKE pods and carries the health check that determines endpoint eligibility. Without it, the global HTTP(S) load balancer cannot route requests or perform health checking.
- ✗
A Kubernetes Service of type LoadBalancer
Why it's wrong here
A Service of type LoadBalancer provisions a regional TCP or HTTP(S) load balancer, not a global one, and cannot attach Cloud CDN. It is tempting because it is the quickest way to expose GKE workloads, but the requirement is a global external Application Load Balancer with a backend service and CDN enabled.
- ✗
Cloud VPN tunnel
Why it's wrong here
Cloud VPN builds encrypted tunnels between on-premises networks and a VPC; it carries no HTTP(S) load-balancing or CDN function. It is tempting because hybrid connectivity is a common GKE prerequisite, but internet-facing exposure needs a global forwarding rule and target HTTP(S) proxy, not a tunnel.
Visual reference
Go deeper
Related to this question
Learn chapter
Identity and Access Management (IAM)
Key term
Cloud NAT
Cloud NAT is a managed network address translation service that allows private cloud resources to initiate outbound internet connections while keeping them unreachable from the internet.
Key term
GKE
GKE is Google's managed Kubernetes service that automates deploying, scaling, and managing containerized applications in the cloud.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.