Google PCA Designing for Security and Compliance Practice Question
A company wants to allow users to authenticate to a web application running on Compute Engine using their existing corporate Active Directory credentials without exposing the application to the public internet. Which approach should they use?
⚠ Common exam trap
PCA often tests whether candidates confuse network-level access controls (VPN, firewall rules, client certs) with identity-based zero-trust access (IAP), and whether they understand that IAP requires Cloud Identity integration for AD credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set up Identity-Aware Proxy (IAP) and sync Active Directory to Cloud Identity
Identity-Aware Proxy (IAP) provides zero-trust access control to applications without exposing them to the public internet, and it integrates with Cloud Identity. By syncing on-premises Active Directory to Cloud Identity (via GCDS or federation), users can authenticate with their corporate credentials through IAP, which enforces IAM policies before allowing access to the Compute Engine-hosted app.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a Cloud VPN and allow only corporate IP addresses in firewall rules
Why it's wrong here
A VPN plus IP-based firewall rules authenticates the network path, not users, and cannot validate corporate Active Directory credentials. It is tempting because VPNs privately connect corporate networks to Google Cloud, and would be correct for restricting administrative access to internal services rather than end-user application sign-in.
- ✓
Set up Identity-Aware Proxy (IAP) and sync Active Directory to Cloud Identity
Why this is correct
IAP enforces identity verification at the load balancer, letting corporate Active Directory users reach the private Compute Engine app without a public IP. Syncing AD to Cloud Identity federates those credentials, satisfying both the authentication and no-public-exposure constraints.
- ✗
Use Cloud Load Balancing with SSL and client certificates
Why it's wrong here
SSL with client certificates authenticates devices holding issued certificates, not users against corporate Active Directory, and requires exposing the load balancer. It is tempting because mutual TLS restricts access to trusted clients, and would be correct for machine-to-machine or partner API access rather than employee sign-in.
- ✗
Configure Cloud NAT and assign static IPs to users
Why it's wrong here
Cloud NAT provides outbound internet egress for instances without public addresses; it performs no inbound authentication and cannot validate Active Directory credentials. It is tempting because NAT keeps instances off the public internet, and would be correct for giving private instances outbound access for updates or API calls.
Go deeper
Related to this question
Learn chapter
Virtual Machine Instances in Compute Engine
Key term
CAN
A CAN (Controller Area Network) is a robust vehicle bus standard designed to allow microcontrollers and devices to communicate with each other without a host computer.
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.