Google PCA Designing for Security and Compliance Practice Question
A company wants to deploy a web application behind an HTTPS Load Balancer and only allow authenticated users from their corporate Active Directory. Which two services should they use together? (Choose two.)
⚠ Common exam trap
PCA often tests the combination of IAP and Cloud Identity for AD-integrated access — candidates may pick Cloud Armor thinking it handles authentication, but Cloud Armor is a WAF, not an identity provider.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identity-Aware Proxy (IAP)
Identity-Aware Proxy (IAP) [CORRECT] is the right choice because it enforces authentication and authorization at the application layer for HTTPS Load Balancer backends, verifying user identity before any request reaches the web application. Cloud Identity [CORRECT] is also correct because it can federate with the corporate Active Directory (via SAML or secure LDAP), providing the identity source that IAP uses to authenticate and authorize corporate users. Together, IAP and Cloud Identity let the company restrict access to authenticated AD users without exposing the app publicly. VPC Service Controls is incorrect because it guards GCP API/service perimeters rather than end-user web application authentication. Cloud NAT is incorrect because it provides outbound internet access for private instances, not user authentication. Cloud Armor is incorrect because it provides WAF/DDoS protection and IP-based rules, not identity-based authentication against Active Directory.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Identity-Aware Proxy (IAP)
Why this is correct
Identity-Aware Proxy enforces authentication and authorisation at the load balancer layer, verifying user identity before granting access to the backend application. It integrates with external identity providers, satisfying the requirement to restrict access to authenticated corporate Active Directory users.
- ✗
VPC Service Controls
Why it's wrong here
VPC Service Controls builds a perimeter around Google Cloud APIs to block data exfiltration, not to authenticate users; it cannot verify corporate Active Directory identities or issue tokens. It is tempting because it enforces access boundaries, and would be correct when restricting which projects may reach a sensitive API from outside a defined perimeter.
- ✗
Cloud NAT
Why it's wrong here
Cloud NAT lets private instances reach the internet outbound without external IP addresses. It performs no user authentication and cannot restrict access by corporate directory membership. It would be correct for giving private subnets egress, not for gating HTTPS Load Balancer traffic to authenticated Active Directory users.
- ✓
Cloud Identity
Why this is correct
Cloud Identity provides the identity provider and directory that IAP uses to authenticate users. Federating it with corporate Active Directory supplies the user identities, satisfying the requirement that only authenticated corporate AD users reach the application.
- ✗
Cloud Armor
Why it's wrong here
Cloud Armor provides WAF rules and DDoS filtering at the edge; it does not authenticate users against Active Directory. Identity-aware proxy or IAP with Microsoft Entra ID integration handles that authentication. Cloud Armor would be correct for blocking SQL injection or geo-based traffic.
Visual reference
Go deeper
Related to this question
Learn chapter
Identity and Access Management (IAM)
Key term
CAN
A CAN (Controller Area Network) is a robust vehicle bus standard designed to allow microcontrollers and devices to communicate with each other without a host computer.
Key term
WAF
A Web Application Firewall (WAF) is a security tool that filters, monitors, and blocks HTTP traffic to and from a web application to protect it from common attacks.
About these practice questions
Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.