Courseiva

Google PCA Manage and provision cloud infrastructure Practice Question

A startup is deploying a new web application on Compute Engine. The application runs on a managed instance group and must be accessible from the internet over HTTP and HTTPS. The security team requires that the application be protected against common web attacks such as SQL injection and cross-site scripting. Which Google Cloud service should the architect use to meet these requirements?

⚠ Common exam trap

Test-takers frequently confuse network-layer firewall rules or identity-based access controls with application-layer WAF protection, which Cloud Armor specifically provides.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cloud Armor with a security policy attached to the backend service of an external HTTP(S) load balancer.

Cloud Armor is the correct service because it provides a web application firewall with preconfigured rules for SQL injection and cross-site scripting, and it integrates directly with external HTTP(S) load balancers. Attaching a security policy to the backend service enforces these protections at the edge before traffic reaches the application.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Identity-Aware Proxy (IAP) with OAuth consent screen and context-aware access policies.

    Why it's wrong here

    IAP controls access to applications based on user identity and context, but it does not perform deep packet inspection to block SQL injection or cross-site scripting. It is an authentication and authorization layer, not a web application firewall, so it does not satisfy the attack protection requirement.

  • ✓

    Cloud Armor with a security policy attached to the backend service of an external HTTP(S) load balancer.

    Why this is correct

    Cloud Armor security policies can be attached to the backend service of an external HTTP(S) load balancer. It provides preconfigured WAF rules for SQL injection and cross-site scripting, as well as IP allowlisting and denylisting. This directly meets the requirement to protect the application from common web attacks.

  • ✗

    VPC firewall rules that allow only HTTP and HTTPS traffic to the managed instance group.

    Why it's wrong here

    VPC firewall rules operate at the network layer and can restrict traffic by port and protocol, but they cannot inspect application-layer payloads to detect SQL injection or cross-site scripting. They provide network segmentation, not web application firewall capabilities, so they fail to protect against the specified attacks.

  • ✗

    Cloud CDN with signed URLs and origin access identity to restrict access to the backend instances.

    Why it's wrong here

    Cloud CDN caches content at the edge and can use signed URLs for access control, but it does not inspect HTTP requests for SQL injection or cross-site scripting. It is designed for content delivery and caching, not for web application firewall protection, so it does not meet the security requirement.

About these practice questions

Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.