Courseiva

Google PCA Designing for Security and Compliance Practice Question

An organization wants to protect an HTTPS load-balanced web application from common web attacks, such as SQL injection and cross-site scripting (XSS), as well as rate-limit traffic from specific IPs. Which three capabilities should they use together? (Choose three.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cloud Armor rate limiting

Cloud Armor WAF rules (C) are correct because Cloud Armor's preconfigured WAF rulesets, based on the ModSecurity core rule set, are specifically designed to detect and block common web attacks like SQL injection and XSS at the load balancer edge. Cloud Armor rate limiting (A) is correct because it lets you define rate-based rules that throttle or ban clients exceeding a request threshold, which directly addresses rate-limiting traffic from specific IPs. Cloud Armor IP blacklist/whitelist (E) is correct because it allows allow/deny rules scoped to specific source IP addresses or CIDR ranges, which is needed to block or permit traffic from particular IPs. Cloud CDN (B) is not correct because it is a content caching and delivery service, not a security control for WAF or rate limiting. Cloud Load Balancing logging (D) is not correct because it only records request data for visibility and auditing; it does not block attacks or enforce rate limits.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Cloud Armor rate limiting

    Why this is correct

    Cloud Armor rate limiting enforces per-IP throttling at the Google Cloud edge, satisfying the requirement to restrict traffic from specific addresses. Combined with its preconfigured WAF rules for SQL injection and XSS, it addresses the attack-mitigation constraint directly, protecting the HTTPS load-balanced backend without application changes.

  • ✗

    Cloud CDN

    Why it's wrong here

    Cloud CDN caches and accelerates HTTP content at edge locations; it inspects no request payloads and applies no WAF rule sets or IP-based rate limiting. It is tempting because it fronts HTTPS load-balanced applications, but that scenario needs Cloud Armor security policies attached to the backend service.

  • ✓

    Cloud Armor WAF rules

    Why this is correct

    Cloud Armor WAF rules inspect HTTP/S requests at the load balancer, applying preconfigured ModSecurity rules to block SQL injection and XSS, while its rate-limiting rules throttle traffic from specified IP addresses. This directly satisfies the stem's requirement for web attack protection plus per-IP rate limiting on the HTTPS load-balanced application.

  • ✗

    Cloud Load Balancing logging

    Why it's wrong here

    Cloud Load Balancing logging records request and latency metrics for observability; it neither inspects payloads for SQL injection or XSS nor enforces IP rate limits. It is tempting because it sits on the same load balancer, but Cloud Armor security policies provide the required filtering and throttling.

  • ✓

    Cloud Armor IP blacklist/whitelist

    Why this is correct

    Cloud Armor IP blacklist/whitelist rules let the load balancer allow or deny traffic by source IP address, delivering the rate-limiting and IP-based filtering the scenario requires. Combined with WAF rules for SQL injection and XSS, it satisfies the protection requirement.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.