Courseiva

Google PCA Design and plan a cloud solution architecture Practice Question

Match each GCP security service to its function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Manage encryption keys

Hardware security module for key protection

Store API keys, passwords, certificates

Manage access control

Centralized security and risk management

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cloud Armor: Protects against DDoS attacks and web application firewall

Cloud Armor protects against DDoS and web attacks; IAP controls access based on identity; KMS handles encryption keys; DLP protects sensitive data. Distractors swap these functions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Cloud Armor: Protects against DDoS attacks and web application firewall

    Why this is correct

    Cloud Armor provides DDoS protection and WAF capabilities.

  • ✓

    Cloud Identity-Aware Proxy (IAP): Controls access to applications based on user identity and context

    Why this is correct

    IAP uses identity and context to enforce access control.

  • ✓

    Cloud Key Management Service (KMS): Manages encryption keys for cloud services

    Why this is correct

    KMS handles creation, rotation, and management of encryption keys.

  • ✓

    Cloud Data Loss Prevention (DLP): Scans and masks sensitive data to prevent leaks

    Why this is correct

    DLP discovers and redacts sensitive data like PII.

  • ✗

    Cloud Armor: Manages encryption keys for cloud services

    Why it's wrong here

    Incorrect — this describes Cloud KMS, not Cloud Armor.

  • ✗

    Cloud Identity-Aware Proxy (IAP): Scans for vulnerabilities in compute instances

    Why it's wrong here

    Incorrect — scanning for vulnerabilities is done by Security Command Center or Web Security Scanner, not IAP.

About these practice questions

Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.