You will host a containerized web app behind a global load balancer with managed SSL and want to offload auth and certificate management using managed services. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Host on GKE and use Identity-Aware Proxy with Cloud Load Balancing and Google-managed certificates..
Why this is the answer
The correct solution leverages Google-managed services for both authentication and SSL. Hosting on GKE provides a robust container orchestration platform. Identity-Aware Proxy (IAP) integrates with Cloud Load Balancing to provide granular, context-aware access control and authentication offloading without modifying the application. Google-managed certificates automatically handle SSL certificate provisioning and renewal, simplifying operations. The other options are less ideal because: Deploying an NGINX Ingress Controller for authentication or cert-manager for SSL on GKE introduces additional operational overhead and requires managing these components yourself, rather than using fully managed Google services. Hosting on Compute Engine and configuring Cloud Endpoints is a valid approach for APIs but is less direct for a web application requiring IAP for authentication and managed SSL through Cloud Load Balancing.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed