Courseiva

Google PCA Designing for Security and Compliance Practice Question

A company wants to allow users to authenticate to a web application running on Compute Engine using their existing corporate Active Directory credentials without exposing the application to the public internet. Which approach should they use?

⚠ Common exam trap

PCA often tests whether candidates confuse network-level access controls (VPN, firewall rules, client certs) with identity-based zero-trust access (IAP), and whether they understand that IAP requires Cloud Identity integration for AD credentials.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set up Identity-Aware Proxy (IAP) and sync Active Directory to Cloud Identity

Identity-Aware Proxy (IAP) provides zero-trust access control to applications without exposing them to the public internet, and it integrates with Cloud Identity. By syncing on-premises Active Directory to Cloud Identity (via GCDS or federation), users can authenticate with their corporate credentials through IAP, which enforces IAM policies before allowing access to the Compute Engine-hosted app.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a Cloud VPN and allow only corporate IP addresses in firewall rules

    Why it's wrong here

    A VPN plus IP-based firewall rules authenticates the network path, not users, and cannot validate corporate Active Directory credentials. It is tempting because VPNs privately connect corporate networks to Google Cloud, and would be correct for restricting administrative access to internal services rather than end-user application sign-in.

  • ✓

    Set up Identity-Aware Proxy (IAP) and sync Active Directory to Cloud Identity

    Why this is correct

    IAP enforces identity verification at the load balancer, letting corporate Active Directory users reach the private Compute Engine app without a public IP. Syncing AD to Cloud Identity federates those credentials, satisfying both the authentication and no-public-exposure constraints.

  • ✗

    Use Cloud Load Balancing with SSL and client certificates

    Why it's wrong here

    SSL with client certificates authenticates devices holding issued certificates, not users against corporate Active Directory, and requires exposing the load balancer. It is tempting because mutual TLS restricts access to trusted clients, and would be correct for machine-to-machine or partner API access rather than employee sign-in.

  • ✗

    Configure Cloud NAT and assign static IPs to users

    Why it's wrong here

    Cloud NAT provides outbound internet egress for instances without public addresses; it performs no inbound authentication and cannot validate Active Directory credentials. It is tempting because NAT keeps instances off the public internet, and would be correct for giving private instances outbound access for updates or API calls.

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.