Courseiva

Google PCA Practice Question: Analyze and optimize technical and business processes

A company uses Cloud Armor to protect their HTTP load balancer. They need to block traffic from a specific set of IP addresses and also prevent SQL injection attacks. Which two configurations should they use? (Choose TWO.)

⚠ Common exam trap

A common mix-up: candidates confuse network-layer controls (firewall rules, VPC ingress) with application-layer protection (WAF), or think IAM roles can filter traffic, when in fact Cloud Armor is the only service that combines IP-based deny rules with WAF capabilities for HTTP load balancers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security policies with IP deny rules

Option D is correct because Cloud Armor security policies support IP deny rules (e.g., a rule with action 'deny(403)' and a srcIpRanges match condition) that block traffic from a specified set of source IP addresses at the HTTP(S) load balancer edge. Option E is correct because Cloud Armor provides preconfigured WAF rules, including the 'sqli' (SQL injection) rule set based on ModSecurity CRS signatures, which detect and block SQL injection attempts when attached to the backend service. Options A, B, and C are incorrect: IAM roles govern identity and API access rather than filtering malicious HTTP traffic, VM firewall rules and VPC ingress rules operate at Layers 3/4 on instances or subnets and cannot inspect HTTP payloads for SQL injection, and they are not the Cloud Armor mechanism for protecting an HTTP(S) load balancer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IAM roles to restrict access

    Why it's wrong here

    IAM roles control identity and API permissions, not network-layer traffic filtering, so they cannot block source IP addresses or inspect HTTP requests for SQL injection. They are tempting because IAM governs who may reach resources, but would be correct for authorising users and service accounts rather than filtering packets.

  • ✗

    Firewall rules on the VM instances

    Why it's wrong here

    Firewall rules on VM instances apply to the instances themselves, not to the HTTP load balancer's edge, so they cannot filter traffic before it reaches the load balancer. They are tempting because they block IP ranges, but would be correct for protecting instances directly rather than a load-balanced frontend.

  • ✗

    Ingress rules on the VPC network

    Why it's wrong here

    Cloud Armor security policies attach to backend services behind the HTTP(S) load balancer; VPC ingress firewall rules operate at the network layer on IP/port/protocol only, so they cannot inspect HTTP requests for SQL injection patterns. Firewall rules would be the right choice for blocking IP ranges at the network perimeter, not application-layer attacks.

  • ✓

    Security policies with IP deny rules

    Why this is correct

    IP deny rules in a Cloud Armor security policy match source addresses at the edge, dropping packets from the specified set before they reach the load balancer. This directly satisfies the requirement to block traffic from named IP addresses, independently of the SQL injection filtering handled by WAF rules.

  • ✓

    Web Application Firewall (WAF) rules with SQL injection preconfigured rules

    Why this is correct

    Cloud Armor's preconfigured WAF rules evaluate request payloads against OWASP signatures, detecting and blocking SQL injection patterns such as UNION SELECT or tautologies. This satisfies the stem's requirement to prevent SQL injection, complementing the separate IP deny rules that handle address blocking.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.