Courseiva

Google PCA Design and plan a cloud solution architecture Practice Question

A retail company operates a global e-commerce platform on Google Cloud. Their architects need to choose a load balancing solution that terminates TLS at the edge, provides a single global anycast IP address, and automatically routes users to the closest healthy backend. Which Google Cloud load balancing product should they select?

⚠ Common exam trap

The trap here is assuming any Application Load Balancer is global, when in fact regional and internal variants exist that lack the single global anycast IP and edge TLS behavior.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Global external Application Load Balancer (HTTP(S))

The global external Application Load Balancer is built for internet-facing global services: it provides a single anycast IP, terminates TLS at Google's edge, and uses Google's global network to send each user to the nearest healthy backend. A regional load balancer cannot give one global IP, and layer 4 passthrough options do not terminate TLS or perform HTTP-aware global routing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Internal Application Load Balancer (HTTP(S))

    Why it's wrong here

    An internal Application Load Balancer is designed for private, internal-only traffic within a VPC network and is not reachable from the public internet. Since the e-commerce platform must serve external users worldwide with a global anycast IP, this internal option cannot fulfill the public-facing edge TLS termination and global routing needs.

  • ✗

    Regional external Application Load Balancer (HTTP(S))

    Why it's wrong here

    A regional external Application Load Balancer terminates TLS and balances HTTP(S) traffic, but its IP address is regional rather than a single global anycast address, and it does not perform global proximity-based routing. For a worldwide e-commerce platform needing one global IP and closest-backend selection, this regional option does not satisfy the design goals.

  • ✓

    Global external Application Load Balancer (HTTP(S))

    Why this is correct

    The global external Application Load Balancer uses a single global anycast IP, terminates TLS at Google's edge, and routes traffic to the closest healthy backend using Google's global network. This matches all three requirements: edge TLS termination, one global IP, and proximity-based routing for a worldwide e-commerce audience.

  • ✗

    External passthrough Network Load Balancer

    Why it's wrong here

    The external passthrough Network Load Balancer operates at layer 4 and does not terminate TLS; it forwards encrypted traffic to backends, so certificates would need to be handled by the instances themselves. It also lacks global anycast fronting and HTTP-aware routing, making it unsuitable for the stated edge TLS termination and global routing requirements.

Go deeper

Related to this question

About these practice questions

Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.