Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A retail company hosts a set of microservices on Google Kubernetes Engine (GKE) behind an external Application Load Balancer. During flash sale events, public client applications generate massive sudden surges in API requests that overload backend database services. Additionally, security teams require verified identity for third-party developers, web application firewall (WAF) filtering against OWASP Top 10 vulnerabilities, and mitigation against automated bot traffic.
Which multi-layered architecture should you recommend to meet these requirements?
Configure Cloud Identity-Aware Proxy (IAP) on the GKE backend services and implement Cloud Armor Layer 7 rate limiting rules on the external Application Load Balancer
Deploy regional Managed Instance Groups with outlier detection policies and require mutual TLS (mTLS) client certificates on all public consumer requests
Configure an external Application Load Balancer with Cloud Armor and reCAPTCHA Enterprise integrated with Apigee as an API gateway using Spike Arrest and OAuth 2.0 verification policies
Pass static API keys as URL query parameters in client requests and configure URL map fault injection policies to throttle traffic
Configure Cloud Identity-Aware Proxy (IAP) on the GKE backend services and implement Cloud Armor Layer 7 rate limiting rules on the external Application Load Balancer
Deploy regional Managed Instance Groups with outlier detection policies and require mutual TLS (mTLS) client certificates on all public consumer requests
Configure an external Application Load Balancer with Cloud Armor and reCAPTCHA Enterprise integrated with Apigee as an API gateway using Spike Arrest and OAuth 2.0 verification policies
This architecture combines Google Cloud Armor, reCAPTCHA Enterprise, and Apigee into a unified Web App and API Protection (WAAP) solution. Apigee acts as the enterprise API management gateway, while Cloud Armor and reCAPTCHA handle edge security and bot mitigation.
Combining Cloud Armor, reCAPTCHA, and Apigee directly satisfies edge perimeter security, bot mitigation, API credential verification, and traffic smoothing, whereas standalone load balancing or firewall rules cannot provide application-level API governance.
Pass static API keys as URL query parameters in client requests and configure URL map fault injection policies to throttle traffic