Google PCA Design for security and compliance Practice Question
A financial services company runs a containerized trading platform on Google Kubernetes Engine (GKE). Compliance requires that all inter-pod traffic be encrypted without modifying application code, and that the encryption keys be managed by the company rather than Google. The security team wants to enforce this at the infrastructure level. Which approach should they take?
⚠ Common exam trap
The trap here is assuming that GKE NetworkPolicy or VPC Service Controls provide encryption, when they only control traffic flow or API perimeters.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure Istio with mutual TLS (mTLS) and a custom certificate authority managed by the company.
Istio's mutual TLS encrypts all service-to-service traffic within the mesh without requiring application changes. By integrating Istio's certificate authority with a company-managed CA, the organization retains control over encryption keys. NetworkPolicy and VPC Service Controls do not encrypt traffic, and Application-layer Secrets Encryption only protects secrets at rest, not network data in transit.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure Istio with mutual TLS (mTLS) and a custom certificate authority managed by the company.
Why this is correct
Istio with mTLS encrypts all service-to-service traffic transparently without application changes. When you integrate Istio's certificate authority with a company-managed CA, the keys and certificates are controlled by the organization, satisfying the requirement that keys be company-managed. This approach enforces encryption at the infrastructure layer for all inter-pod communication.
- ✗
Enable Application-layer Secrets Encryption with a Cloud KMS key on the GKE cluster.
Why it's wrong here
Application-layer Secrets Encryption protects Kubernetes Secrets stored in etcd, not inter-pod network traffic. It uses a Cloud KMS key to encrypt secret data at rest, but it does not provide encryption for pod-to-pod communication. This option addresses a different security concern and would leave inter-pod traffic unencrypted, failing the compliance requirement.
- ✗
Use VPC Service Controls to create a service perimeter around the GKE cluster.
Why it's wrong here
VPC Service Controls define security perimeters around Google Cloud services to mitigate data exfiltration, but they do not encrypt traffic between pods. They operate at the API level for managed services and do not provide in-cluster encryption. This option would not encrypt inter-pod communication and thus fails to meet the compliance requirement.
- ✗
Enable GKE network policy enforcement and create NetworkPolicy resources to allow only encrypted traffic.
Why it's wrong here
GKE NetworkPolicy controls which pods can communicate, but it does not encrypt traffic. NetworkPolicy operates at layers 3 and 4 to allow or deny connections based on labels and ports; it cannot enforce encryption. Enabling it would restrict traffic flow but leave data in plaintext, so it does not meet the encryption requirement.
Go deeper
Related to this question
Learn chapter
Cloud SQL and Managed Data Stores
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
Key term
Certificate authority
A trusted entity that issues digital certificates to verify the identity of websites, devices, and users in secure online communications.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.