You have an instance group serving a public HTTPS website and want the load balancer to terminate client SSL sessions, following Google best practices. Which load balancer should you configure?
Choose an answer
Tap an option to check your answer.
Correct answer: Configure an external HTTP(S) Load Balancer (SSL termination at the load balancer)..
Why this is the answer
For a public HTTPS website, an external HTTP(S) Load Balancer is the correct choice. It's designed for global HTTP(S) traffic, offering SSL termination at the load balancer itself, which is a Google best practice for offloading encryption/decryption from backend instances and centralizing certificate management. An internal TCP Load Balancer is for internal traffic only, not public-facing services. External SSL Proxy and TCP Proxy Load Balancers operate at Layer 4 (TCP/SSL) and are suitable for non-HTTP(S) protocols or when you need to pass encrypted traffic directly to backends, but they don't terminate SSL for HTTP(S) traffic in the way an HTTP(S) Load Balancer does.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed