Courseiva

Google PCA Design for security and compliance Practice Question

A media company runs a public web application behind a global external Application Load Balancer. They need to block traffic from specific countries subject to sanctions and rate-limit abusive clients, all without changing application code. Which Google Cloud service should the architect configure?

⚠ Common exam trap

The trap here is assuming that VPC firewall rules, which operate on IP and port, can enforce country-based blocking or per-client HTTP rate limiting for a proxied load balancer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cloud Armor security policies with geographic-based rules and rate-based ban rules attached to the backend service

Cloud Armor security policies bind to the backend service of an external Application Load Balancer and inspect requests at Google's edge. Geographic rules deny traffic by source region, and rate-based ban rules throttle or temporarily ban clients exceeding thresholds, delivering sanctions blocking and abuse mitigation without modifying the application.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VPC firewall rules applied to the load balancer's backend instances

    Why it's wrong here

    VPC firewall rules filter by IP, protocol, and port but have no notion of client country and cannot rate-limit HTTP requests. Because the load balancer proxies traffic, backend firewall rules see Google's proxy addresses rather than the original client, making geographic blocking and abuse throttling impossible at that layer.

  • ✗

    Identity-Aware Proxy with context-aware access levels based on device and location

    Why it's wrong here

    IAP gates access to applications using identity and context, which is suited to internal or workforce apps rather than anonymous public traffic. It does not offer country-based denial for unauthenticated users or request-rate throttling, so it cannot implement the sanctions blocking or abuse rate limiting described.

  • ✓

    Cloud Armor security policies with geographic-based rules and rate-based ban rules attached to the backend service

    Why this is correct

    Cloud Armor attaches to the load balancer's backend service and evaluates requests at Google's edge. Geographic rules can deny traffic from sanctioned regions, and rate-based ban rules throttle or block clients exceeding configured thresholds, all declaratively and without application changes, matching the requirement exactly.

  • ✗

    Cloud CDN with signed URLs and cache key policies

    Why it's wrong here

    Cloud CDN accelerates content and can restrict access via signed URLs, but it does not perform geographic blocking or client rate limiting. It caches responses at the edge; it cannot evaluate source country or enforce per-client request quotas, so the sanctions and abuse requirements remain unaddressed.

About these practice questions

Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.