Google PCA Design and plan a cloud solution architecture Practice Question
A retail company is designing a new order-processing system on Google Cloud. The system must expose a REST API that is reachable from the public internet over a custom hostname, must terminate TLS at the edge, and must route requests to different backend services based on URL path prefixes such as /orders and /inventory. The platform team wants a fully managed, globally distributed solution that scales automatically and does not require managing reverse-proxy VMs. Which Google Cloud component should they place in front of the backends?
⚠ Common exam trap
The trap here is assuming that any load balancer can perform HTTP path-based routing, when Layer 4 passthrough network load balancers only forward TCP connections.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Global external Application Load Balancer with a URL map and a Google-managed SSL certificate
The global external Application Load Balancer is the only listed option that combines managed edge TLS termination, custom hostname support through Google-managed certificates, and URL-map-based path routing to multiple backends. Because it is a fully managed global proxy, it scales automatically and removes the operational burden of running reverse-proxy VMs, satisfying both the functional and operational requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Traffic Director with Envoy sidecars deployed on each backend instance
Why it's wrong here
Traffic Director is a control plane for service mesh and proxyless gRPC workloads, not a public edge HTTP entry point. Using it here would require running and managing Envoy sidecars, which contradicts the requirement for a fully managed solution that avoids managing proxy infrastructure, and it does not natively provide Google-managed edge certificates for a public hostname.
- ✗
Regional external passthrough Network Load Balancer with backend services in two zones
Why it's wrong here
A passthrough Network Load Balancer operates at Layer 4 and forwards TCP without inspecting HTTP, so it cannot route by URL path prefixes such as /orders or /inventory. It also does not terminate TLS at the edge or provide centralized managed certificate hosting, so it fails the routing and TLS requirements in this scenario.
- ✓
Global external Application Load Balancer with a URL map and a Google-managed SSL certificate
Why this is correct
The global external Application Load Balancer is a managed Layer 7 proxy that terminates TLS at Google's edge, supports custom hostnames through Google-managed certificates, and uses a URL map to route by path prefix to different backends. It scales globally without reverse-proxy VMs, which matches every stated requirement.
- ✗
Cloud CDN with a signed URL key attached directly to the backend instance groups
Why it's wrong here
Cloud CDN is a caching layer that must be attached to a supported load balancer; it is not itself a front-end routing or TLS-termination component. It also caches content rather than routing dynamic API requests by path prefix, so it cannot satisfy the requirement to split traffic between the order and inventory backends.
Go deeper
Related to this question
Learn chapter
Cloud SQL and Managed Data Stores
Key term
Load balancer
A load balancer is a device or software that distributes incoming network traffic across multiple servers so no single server gets overwhelmed.
Key term
Route
A route is a path that data takes through a network from one device or network to another, determined by routing protocols and configured rules.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.