Courseiva

Google PCA Designing for Security and Compliance Practice Question

A company wants to deploy a web application behind an HTTPS Load Balancer and only allow authenticated users from their corporate Active Directory. Which two services should they use together? (Choose two.)

⚠ Common exam trap

PCA often tests the combination of IAP and Cloud Identity for AD-integrated access — candidates may pick Cloud Armor thinking it handles authentication, but Cloud Armor is a WAF, not an identity provider.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identity-Aware Proxy (IAP)

Identity-Aware Proxy (IAP) [CORRECT] is the right choice because it enforces authentication and authorization at the application layer for HTTPS Load Balancer backends, verifying user identity before any request reaches the web application. Cloud Identity [CORRECT] is also correct because it can federate with the corporate Active Directory (via SAML or secure LDAP), providing the identity source that IAP uses to authenticate and authorize corporate users. Together, IAP and Cloud Identity let the company restrict access to authenticated AD users without exposing the app publicly. VPC Service Controls is incorrect because it guards GCP API/service perimeters rather than end-user web application authentication. Cloud NAT is incorrect because it provides outbound internet access for private instances, not user authentication. Cloud Armor is incorrect because it provides WAF/DDoS protection and IP-based rules, not identity-based authentication against Active Directory.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Identity-Aware Proxy (IAP)

    Why this is correct

    Identity-Aware Proxy enforces authentication and authorisation at the load balancer layer, verifying user identity before granting access to the backend application. It integrates with external identity providers, satisfying the requirement to restrict access to authenticated corporate Active Directory users.

  • ✗

    VPC Service Controls

    Why it's wrong here

    VPC Service Controls builds a perimeter around Google Cloud APIs to block data exfiltration, not to authenticate users; it cannot verify corporate Active Directory identities or issue tokens. It is tempting because it enforces access boundaries, and would be correct when restricting which projects may reach a sensitive API from outside a defined perimeter.

  • ✗

    Cloud NAT

    Why it's wrong here

    Cloud NAT lets private instances reach the internet outbound without external IP addresses. It performs no user authentication and cannot restrict access by corporate directory membership. It would be correct for giving private subnets egress, not for gating HTTPS Load Balancer traffic to authenticated Active Directory users.

  • ✓

    Cloud Identity

    Why this is correct

    Cloud Identity provides the identity provider and directory that IAP uses to authenticate users. Federating it with corporate Active Directory supplies the user identities, satisfying the requirement that only authenticated corporate AD users reach the application.

  • ✗

    Cloud Armor

    Why it's wrong here

    Cloud Armor provides WAF rules and DDoS filtering at the edge; it does not authenticate users against Active Directory. Identity-aware proxy or IAP with Microsoft Entra ID integration handles that authentication. Cloud Armor would be correct for blocking SQL injection or geo-based traffic.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.