Courseiva

Google PCA Design and plan a cloud solution architecture Practice Question

Your organization is deploying a global e-commerce platform on Google Cloud. The platform uses a microservices architecture running on GKE, and you need to route external HTTP(S) traffic to different services based on URL paths and also provide global load balancing with low latency. You also want to offload SSL/TLS termination and protect against DDoS attacks. Which Google Cloud service should you use?

⚠ Common exam trap

The trap here is assuming that a regional load balancer or a TCP proxy can provide global HTTP(S) routing with path-based rules, when only the global external HTTP(S) Load Balancer offers all these features together.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Global external HTTP(S) Load Balancer with a URL map and Google-managed SSL certificates, integrated with Cloud Armor.

The global external HTTP(S) Load Balancer is the only option that provides global anycast load balancing, URL path-based routing, Google-managed SSL certificates for TLS termination, and integration with Cloud Armor for DDoS protection. It is designed for external HTTP(S) traffic and meets all the stated requirements for a global e-commerce platform.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Internal HTTP(S) Load Balancer with a URL map and Google-managed SSL certificates, integrated with Cloud Armor.

    Why it's wrong here

    Internal HTTP(S) Load Balancer is designed for internal traffic within a VPC, not for external users. It cannot route external HTTP(S) traffic from the internet. While it supports URL maps and SSL, it is not accessible externally, so it fails the requirement for a global e-commerce platform serving external customers.

  • ✗

    TCP Proxy Load Balancer with a backend service and Google-managed SSL certificates, integrated with Cloud Armor.

    Why it's wrong here

    TCP Proxy Load Balancer operates at layer 4 and does not support URL path-based routing, which is required for routing based on URL paths. It can provide global load balancing and SSL termination, but it cannot inspect HTTP headers or paths. Cloud Armor integration is limited for TCP proxy, and it does not meet the need for HTTP(S) path-based routing.

  • ✓

    Global external HTTP(S) Load Balancer with a URL map and Google-managed SSL certificates, integrated with Cloud Armor.

    Why this is correct

    The global external HTTP(S) Load Balancer provides global anycast IP, low-latency routing, and URL path-based routing via URL maps. It supports Google-managed SSL certificates for TLS termination and integrates with Cloud Armor for DDoS protection and WAF rules. This meets all requirements: global load balancing, path-based routing, SSL offload, and DDoS mitigation.

  • ✗

    Regional external HTTP(S) Load Balancer with a URL map and self-managed SSL certificates, integrated with Cloud CDN.

    Why it's wrong here

    A regional load balancer does not provide global anycast IP or global low-latency routing; it only serves a single region. While it supports URL maps and SSL termination, it lacks the global reach and DDoS protection of the global load balancer with Cloud Armor. Cloud CDN can improve performance but does not replace global load balancing or DDoS protection.

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.