Google PCA Designing for Security and Compliance Practice Question
An organization wants to protect an HTTPS load-balanced web application from common web attacks, such as SQL injection and cross-site scripting (XSS), as well as rate-limit traffic from specific IPs. Which three capabilities should they use together? (Choose three.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud Armor rate limiting
Cloud Armor WAF rules (C) are correct because Cloud Armor's preconfigured WAF rulesets, based on the ModSecurity core rule set, are specifically designed to detect and block common web attacks like SQL injection and XSS at the load balancer edge. Cloud Armor rate limiting (A) is correct because it lets you define rate-based rules that throttle or ban clients exceeding a request threshold, which directly addresses rate-limiting traffic from specific IPs. Cloud Armor IP blacklist/whitelist (E) is correct because it allows allow/deny rules scoped to specific source IP addresses or CIDR ranges, which is needed to block or permit traffic from particular IPs. Cloud CDN (B) is not correct because it is a content caching and delivery service, not a security control for WAF or rate limiting. Cloud Load Balancing logging (D) is not correct because it only records request data for visibility and auditing; it does not block attacks or enforce rate limits.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Cloud Armor rate limiting
Why this is correct
Cloud Armor rate limiting enforces per-IP throttling at the Google Cloud edge, satisfying the requirement to restrict traffic from specific addresses. Combined with its preconfigured WAF rules for SQL injection and XSS, it addresses the attack-mitigation constraint directly, protecting the HTTPS load-balanced backend without application changes.
- ✗
Cloud CDN
Why it's wrong here
Cloud CDN caches and accelerates HTTP content at edge locations; it inspects no request payloads and applies no WAF rule sets or IP-based rate limiting. It is tempting because it fronts HTTPS load-balanced applications, but that scenario needs Cloud Armor security policies attached to the backend service.
- ✓
Cloud Armor WAF rules
Why this is correct
Cloud Armor WAF rules inspect HTTP/S requests at the load balancer, applying preconfigured ModSecurity rules to block SQL injection and XSS, while its rate-limiting rules throttle traffic from specified IP addresses. This directly satisfies the stem's requirement for web attack protection plus per-IP rate limiting on the HTTPS load-balanced application.
- ✗
Cloud Load Balancing logging
Why it's wrong here
Cloud Load Balancing logging records request and latency metrics for observability; it neither inspects payloads for SQL injection or XSS nor enforces IP rate limits. It is tempting because it sits on the same load balancer, but Cloud Armor security policies provide the required filtering and throttling.
- ✓
Cloud Armor IP blacklist/whitelist
Why this is correct
Cloud Armor IP blacklist/whitelist rules let the load balancer allow or deny traffic by source IP address, delivering the rate-limiting and IP-based filtering the scenario requires. Combined with WAF rules for SQL injection and XSS, it satisfies the protection requirement.
Visual reference
Go deeper
Related to this question
Learn chapter
Security Best Practices and Compliance
Key term
IPS
An Intrusion Prevention System (IPS) is a network security device that monitors traffic in real time and automatically blocks threats before they reach your systems.
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
About these practice questions
This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.