Google PCA Design for security and compliance Practice Question
An e-commerce company exposes a public API through an external HTTP(S) load balancer on Google Cloud. The security team wants to block traffic from known malicious IP ranges and apply rate limiting per client IP, while keeping legitimate customers unaffected. They want the least operational overhead and no changes to backend applications. What should they do?
⚠ Common exam trap
The trap here is reaching for VPC firewall rules, which operate on backend instances and cannot see the original client IP behind an HTTP(S) load balancer, instead of edge-level Cloud Armor policies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy Cloud Armor security policies with IP deny rules and a rate-based ban rule, and attach the policy to the load balancer's backend service.
Cloud Armor is the native edge security service for external HTTP(S) load balancers, attaching at the backend service where it can evaluate client IP rules and rate-based bans before traffic reaches backends. This satisfies both blocking malicious ranges and per-client-IP throttling without touching application code or managing instance-level firewalls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Deploy Cloud Armor security policies with IP deny rules and a rate-based ban rule, and attach the policy to the load balancer's backend service.
Why this is correct
Cloud Armor security policies attach to the backend service of an external HTTP(S) load balancer and can combine IP denylists with rate-based ban rules that throttle abusive clients per source IP. This requires no backend changes, is managed centrally, and blocks malicious ranges while allowing legitimate traffic, matching the least-overhead requirement.
- ✗
Configure Cloud CDN with signed URLs and require all API clients to authenticate before reaching the backend.
Why it's wrong here
Cloud CDN with signed URLs is designed for content distribution and access control of cacheable content, not for blocking malicious IP ranges or rate limiting API clients. It would also force API clients to change how they authenticate, which conflicts with the requirement to avoid application changes and keep legitimate customers unaffected.
- ✗
Use Identity-Aware Proxy to require Google account authentication for all API requests.
Why it's wrong here
Identity-Aware Proxy authenticates users through Google identities or external IdPs and is suited to internal applications, not public customer APIs. It does not provide IP denylisting or per-IP rate limiting, and requiring Google account authentication would break the public API's existing client authentication model.
- ✗
Create a VPC firewall rule that denies traffic from the malicious IP ranges to the load balancer's backend instances.
Why it's wrong here
VPC firewall rules on the backend instances cannot distinguish client IPs once traffic is proxied by the external HTTP(S) load balancer, because the source appears as the load balancer's internal ranges. They also provide no rate limiting and would require instance-level management, adding operational overhead and not meeting the per-client-IP requirement.
Go deeper
Related to this question
Learn chapter
Deployment Manager and Infrastructure as Code
Key term
Service
A service is a software component or system that performs a specific function and is available to be used by other programs or users over a network.
Key term
HTTP
HTTP stands for Hypertext Transfer Protocol, the set of rules web browsers and servers use to communicate and transfer web pages over the internet.
About these practice questions
This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.