Courseiva

Google PCA Designing for Security and Compliance Practice Question

A company uses Cloud Armor to protect an HTTPS Load Balancer. They want to allow traffic only from users who have passed a reCAPTCHA challenge. Cloud Armor supports which feature for this?

⚠ Common exam trap

PCA often tests whether candidates confuse Cloud Armor's reCAPTCHA enforcement with Adaptive Protection or preconfigured WAF rules; the key is recognizing that only WAF rules with reCAPTCHA token attributes can enforce human verification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

WAF rules with reCAPTCHA

Cloud Armor supports reCAPTCHA integration through WAF rules that use the 'token.recaptcha_session.score' or 'token.recaptcha_action.score' attributes to allow, deny, or redirect traffic based on the reCAPTCHA assessment score. This is configured as a security policy rule with a reCAPTCHA challenge action, enabling the load balancer to enforce human verification before granting access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    WAF rules with reCAPTCHA

    Why this is correct

    Cloud Armor's reCAPTCHA integration is configured through WAF rules using the recaptcha action, which challenges or redirects clients to a reCAPTCHA assessment before allowing traffic to the HTTPS Load Balancer. This enforces the requirement that only users passing the challenge reach the backend.

  • ✗

    Preconfigured WAF rules

    Why it's wrong here

    Preconfigured WAF rules match known attack signatures such as SQL injection and XSS; they do not present a reCAPTCHA challenge or check a challenge token. They are tempting as a ready-made Cloud Armor security control, but the reCAPTCHA gate needs the bot-management challenge rule instead.

  • ✗

    Adaptive Protection

    Why it's wrong here

    Adaptive Protection applies machine-learning anomaly detection to flag and block suspicious Layer 7 traffic patterns; it cannot issue or validate a reCAPTCHA challenge. It is tempting because it enforces security at the edge, but the reCAPTCHA gate requires the separate bot-management challenge integration.

  • ✗

    Rate limiting

    Why it's wrong here

    Rate limiting throttles request volume per client IP or key over a time window; it cannot verify that a user completed a reCAPTCHA challenge. It is tempting because it mitigates abusive traffic at the edge, but the reCAPTCHA gate requires the bot-management challenge rule, not a request-rate threshold.

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.