Courseiva

Google PCA Designing for Security and Compliance Practice Question

A startup runs a public API on Compute Engine behind an external HTTP(S) load balancer. The security team wants to block common web attacks such as SQL injection and cross-site scripting at the edge, with minimal changes to the application, and they want the protection rules to be managed centrally and updated as new signatures are released. What should the architect recommend?

⚠ Common exam trap

Test-takers frequently confuse identity-based access control or network firewall rules with application-layer attack filtering, which only Cloud Armor performs at the load balancer edge.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy Cloud Armor security policies with preconfigured WAF rules and attach the policy to the backend service of the external HTTP(S) load balancer.

Cloud Armor is Google Cloud's edge security service that attaches to external HTTP(S) load balancer backend services. Its preconfigured WAF rules, derived from the ModSecurity core rule set, detect and block SQL injection, cross-site scripting, and other OWASP-style attacks. Because Google manages the rule signatures and policies are configured once at the load balancer, the application needs no changes and protection is centralized.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Identity-Aware Proxy on the backend service and require Google account authentication for all API calls.

    Why it's wrong here

    Identity-Aware Proxy controls who can reach the application by verifying identity and context, but it does not inspect request payloads for SQL injection or cross-site scripting patterns. It would also break a public API intended for unauthenticated callers, so it neither provides the requested attack filtering nor fits the access model.

  • ✗

    Install a third-party WAF on each Compute Engine instance and configure it to read request bodies before the application does.

    Why it's wrong here

    Host-based WAFs require installing and maintaining agents on every instance, patching them, and scaling them with the fleet, which is far from minimal change. It also distributes policy management across instances rather than centralizing it, and it does not benefit from Google-managed signature updates delivered through the load balancer.

  • ✓

    Deploy Cloud Armor security policies with preconfigured WAF rules and attach the policy to the backend service of the external HTTP(S) load balancer.

    Why this is correct

    Cloud Armor attaches to the backend service of an external HTTP(S) load balancer and offers preconfigured WAF rules based on the ModSecurity core rule set, covering SQL injection and cross-site scripting. Google maintains and updates the signatures, so the startup gets edge protection without modifying application code, matching the centralized management requirement.

  • ✗

    Create VPC firewall rules that deny traffic containing suspicious URL patterns to the load balancer's forwarding rule.

    Why it's wrong here

    VPC firewall rules operate at Layers 3 and 4 based on IP, protocol, and port; they cannot inspect HTTP request content for SQL injection or script payloads. They also cannot be attached to a load balancer's forwarding rule to filter application-layer attacks, so this approach cannot meet the requirement.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.