Courseiva
Implementing VPC InstanceshardMultiple SelectObjective-mapped

PCNE Implementing VPC Instances Practice Question

A company has an HTTP Load Balancer that distributes traffic to a backend service consisting of Compute Engine instance groups. They need to block traffic from specific geographic regions and also rate-limit requests from any IP. Which THREE Cloud Armor features should they configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Rate limiting rules

Cloud Armor security policies allow you to create rules with conditions. To block regions, use geoblocking by specifying source regions. To rate-limit, use rate limiting rules. Custom rules can also be used to combine conditions. Pre-configured WAF rules (like XSS, SQLi) are for web application attacks, not region blocking or rate limiting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Cloud Armor logging

    Why it's wrong here

    Logging is not a security feature that blocks or rate-limits traffic.

  • Rate limiting rules

    Why this is correct

    Limits the number of requests from a source IP to prevent abuse.

  • Pre-configured WAF rules (e.g., OWASP Top 10)

    Why it's wrong here

    These protect against web exploits, not geoblocking or rate limiting.

  • Geo-based access control (geoblocking)

    Why this is correct

    Enables blocking/allowing traffic from specific countries or regions.

  • Custom rules with IP allow/deny

    Why this is correct

    Can be used to implement geoblocking and rate limiting, but the statement asks for features; geoblocking and rate limiting are specific features.

About these practice questions

This PCNE question is part of Courseiva's 961-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNE exam.