Google PCA Manage and provision cloud infrastructure Practice Question
A startup is deploying a new web application on Compute Engine. The application runs on a managed instance group and must be accessible from the internet over HTTP and HTTPS. The security team requires that the application be protected against common web attacks such as SQL injection and cross-site scripting. Which Google Cloud service should the architect use to meet these requirements?
⚠ Common exam trap
Test-takers frequently confuse network-layer firewall rules or identity-based access controls with application-layer WAF protection, which Cloud Armor specifically provides.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud Armor with a security policy attached to the backend service of an external HTTP(S) load balancer.
Cloud Armor is the correct service because it provides a web application firewall with preconfigured rules for SQL injection and cross-site scripting, and it integrates directly with external HTTP(S) load balancers. Attaching a security policy to the backend service enforces these protections at the edge before traffic reaches the application.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Identity-Aware Proxy (IAP) with OAuth consent screen and context-aware access policies.
Why it's wrong here
IAP controls access to applications based on user identity and context, but it does not perform deep packet inspection to block SQL injection or cross-site scripting. It is an authentication and authorization layer, not a web application firewall, so it does not satisfy the attack protection requirement.
- ✓
Cloud Armor with a security policy attached to the backend service of an external HTTP(S) load balancer.
Why this is correct
Cloud Armor security policies can be attached to the backend service of an external HTTP(S) load balancer. It provides preconfigured WAF rules for SQL injection and cross-site scripting, as well as IP allowlisting and denylisting. This directly meets the requirement to protect the application from common web attacks.
- ✗
VPC firewall rules that allow only HTTP and HTTPS traffic to the managed instance group.
Why it's wrong here
VPC firewall rules operate at the network layer and can restrict traffic by port and protocol, but they cannot inspect application-layer payloads to detect SQL injection or cross-site scripting. They provide network segmentation, not web application firewall capabilities, so they fail to protect against the specified attacks.
- ✗
Cloud CDN with signed URLs and origin access identity to restrict access to the backend instances.
Why it's wrong here
Cloud CDN caches content at the edge and can use signed URLs for access control, but it does not inspect HTTP requests for SQL injection or cross-site scripting. It is designed for content delivery and caching, not for web application firewall protection, so it does not meet the security requirement.
Go deeper
Related to this question
Learn chapter
IAM Policies, Service Accounts, and Auditing
Key term
Instance group
An instance group is a collection of virtual machine instances that are managed as a single unit for scaling, load balancing, and lifecycle management in cloud computing.
Key term
HTTP
HTTP stands for Hypertext Transfer Protocol, the set of rules web browsers and servers use to communicate and transfer web pages over the internet.
About these practice questions
Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.