Courseiva

Google PCA Design for security and compliance Practice Question

A company uses Google Cloud Armor to protect their HTTP load balancer from OWASP Top 10 attacks. After deploying a security policy with pre-configured WAF rules, they notice that some legitimate user requests are being blocked because they match a rule incorrectly. The security team wants to fine-tune the rules to reduce false positives while maintaining strong protection. They also want to evaluate the impact of changes before enforcing them. What should they do?

⚠ Common exam trap

A common mix-up: candidates think adding a higher priority allow rule (Option C) is a valid fine-tuning approach, but it actually creates a security bypass rather than reducing false positives through proper rule adjustment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set the WAF rules to 'preview' mode to test their impact without blocking traffic, then adjust thresholds or exclusions based on logs.

Google Cloud Armor's 'preview' mode allows you to apply a security policy to a backend service or load balancer without actually blocking traffic. Instead, all matched requests are logged, enabling you to analyze false positives in the logs before enforcing the rules. This approach lets you fine-tune thresholds, add exclusions, or adjust rule priorities based on real traffic patterns, reducing false positives while maintaining strong protection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable the WAF rules entirely and implement IP-based allowlists.

    Why it's wrong here

    IP allowlists bypass WAF inspection entirely, so OWASP Top 10 attacks from permitted addresses pass unfiltered and false positives are not tuned. It is tempting because allowlisting is quick and predictable, and it would be correct for restricting administrative access to known corporate egress addresses.

  • ✓

    Set the WAF rules to 'preview' mode to test their impact without blocking traffic, then adjust thresholds or exclusions based on logs.

    Why this is correct

    Preview mode logs which requests would have been blocked without enforcing the action, letting the team measure false positives and tune thresholds or exclusions before enforcement. This satisfies both the fine-tuning and pre-enforcement evaluation requirements while preserving protection.

  • ✗

    Add a higher priority allow rule to permit the traffic that is being incorrectly blocked.

    Why it's wrong here

    A priority allow rule bypasses the offending WAF signature for all matching traffic, including genuinely malicious requests crafted to resemble it, and provides no preview mechanism. Allow rules suit known-trusted source ranges or verified benign paths, not tuning a signature that is misfiring on legitimate payloads.

  • ✗

    Remove the WAF rules and rely solely on rate limiting to protect the application.

    Why it's wrong here

    Removing the WAF rules eliminates OWASP Top 10 coverage entirely, leaving only volumetric rate limiting, which cannot inspect request payloads for injection or XSS patterns. Rate limiting suits denial-of-service absorption, not signature-based attack filtering, so the false positives would vanish only by discarding the protection the stem requires.

About these practice questions

Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.