Courseiva

Google PCA Design for security and compliance Practice Question

An e-commerce company exposes a public API through an external HTTP(S) load balancer on Google Cloud. The security team wants to block traffic from known malicious IP ranges and apply rate limiting per client IP, while keeping legitimate customers unaffected. They want the least operational overhead and no changes to backend applications. What should they do?

⚠ Common exam trap

The trap here is reaching for VPC firewall rules, which operate on backend instances and cannot see the original client IP behind an HTTP(S) load balancer, instead of edge-level Cloud Armor policies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy Cloud Armor security policies with IP deny rules and a rate-based ban rule, and attach the policy to the load balancer's backend service.

Cloud Armor is the native edge security service for external HTTP(S) load balancers, attaching at the backend service where it can evaluate client IP rules and rate-based bans before traffic reaches backends. This satisfies both blocking malicious ranges and per-client-IP throttling without touching application code or managing instance-level firewalls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Deploy Cloud Armor security policies with IP deny rules and a rate-based ban rule, and attach the policy to the load balancer's backend service.

    Why this is correct

    Cloud Armor security policies attach to the backend service of an external HTTP(S) load balancer and can combine IP denylists with rate-based ban rules that throttle abusive clients per source IP. This requires no backend changes, is managed centrally, and blocks malicious ranges while allowing legitimate traffic, matching the least-overhead requirement.

  • ✗

    Configure Cloud CDN with signed URLs and require all API clients to authenticate before reaching the backend.

    Why it's wrong here

    Cloud CDN with signed URLs is designed for content distribution and access control of cacheable content, not for blocking malicious IP ranges or rate limiting API clients. It would also force API clients to change how they authenticate, which conflicts with the requirement to avoid application changes and keep legitimate customers unaffected.

  • ✗

    Use Identity-Aware Proxy to require Google account authentication for all API requests.

    Why it's wrong here

    Identity-Aware Proxy authenticates users through Google identities or external IdPs and is suited to internal applications, not public customer APIs. It does not provide IP denylisting or per-IP rate limiting, and requiring Google account authentication would break the public API's existing client authentication model.

  • ✗

    Create a VPC firewall rule that denies traffic from the malicious IP ranges to the load balancer's backend instances.

    Why it's wrong here

    VPC firewall rules on the backend instances cannot distinguish client IPs once traffic is proxied by the external HTTP(S) load balancer, because the source appears as the load balancer's internal ranges. They also provide no rate limiting and would require instance-level management, adding operational overhead and not meeting the per-client-IP requirement.

About these practice questions

This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.