Google PCA Designing for Security and Compliance Practice Question
A company uses Cloud Armor to protect an HTTPS Load Balancer. They want to allow traffic only from users who have passed a reCAPTCHA challenge. Cloud Armor supports which feature for this?
⚠ Common exam trap
PCA often tests whether candidates confuse Cloud Armor's reCAPTCHA enforcement with Adaptive Protection or preconfigured WAF rules; the key is recognizing that only WAF rules with reCAPTCHA token attributes can enforce human verification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WAF rules with reCAPTCHA
Cloud Armor supports reCAPTCHA integration through WAF rules that use the 'token.recaptcha_session.score' or 'token.recaptcha_action.score' attributes to allow, deny, or redirect traffic based on the reCAPTCHA assessment score. This is configured as a security policy rule with a reCAPTCHA challenge action, enabling the load balancer to enforce human verification before granting access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
WAF rules with reCAPTCHA
Why this is correct
Cloud Armor's reCAPTCHA integration is configured through WAF rules using the recaptcha action, which challenges or redirects clients to a reCAPTCHA assessment before allowing traffic to the HTTPS Load Balancer. This enforces the requirement that only users passing the challenge reach the backend.
- ✗
Preconfigured WAF rules
Why it's wrong here
Preconfigured WAF rules match known attack signatures such as SQL injection and XSS; they do not present a reCAPTCHA challenge or check a challenge token. They are tempting as a ready-made Cloud Armor security control, but the reCAPTCHA gate needs the bot-management challenge rule instead.
- ✗
Adaptive Protection
Why it's wrong here
Adaptive Protection applies machine-learning anomaly detection to flag and block suspicious Layer 7 traffic patterns; it cannot issue or validate a reCAPTCHA challenge. It is tempting because it enforces security at the edge, but the reCAPTCHA gate requires the separate bot-management challenge integration.
- ✗
Rate limiting
Why it's wrong here
Rate limiting throttles request volume per client IP or key over a time window; it cannot verify that a user completed a reCAPTCHA challenge. It is tempting because it mitigates abusive traffic at the edge, but the reCAPTCHA gate requires the bot-management challenge rule, not a request-rate threshold.
Go deeper
Related to this question
Learn chapter
Identity and Access Management (IAM)
Key term
WAF
A Web Application Firewall (WAF) is a security tool that filters, monitors, and blocks HTTP traffic to and from a web application to protect it from common attacks.
Key term
Cloud Armor
Cloud Armor is a Google Cloud web application firewall (WAF) service that protects applications and websites from attacks like DDoS and SQL injection using customizable security rules.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.