How Should You Secure Cloud Run with Browser SSO?

Access Control & IAM
Answer Correct answer: D — Activate Identity-Aware Proxy on the backend and assign the IAP-secured Web App User role to restrict access to authorized users.

You run a web application on top of Cloud Run that is exposed to the internet with an Application Load Balancer. You want to ensure that only privileged users from your organization can access the application. The proposed solution must support browser access with single sign-on. What should you do?

  1. Change Cloud Run configuration to require authentication. Assign the role of Cloud Run Invoker to the group of privileged users.
  2. Create a group of privileged users in Cloud Identity. Assign the role of Cloud Run User to the group directly on the Cloud Run service.
  3. Change the Ingress Control configuration of Cloud Run to internal and create firewall rules to allow only access from known IP addresses.
  4. Activate Identity-Aware Proxy (IAP) on the Application Load Balancer backend. Assign the role of IAP-secured Web App User to the group of privileged users. Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests knowledge of Google Cloud access control mechanisms, specifically distinguishing between native IAM roles and network-level controls versus a dedicated secure gateway like IAP for web SSO.

Securing internet-exposed Cloud Run services requires a centralized authentication proxy that integrates with organizational identity. This page establishes why Identity-Aware Proxy is the correct architectural choice for enforcing browser-based single sign-on.

Learners often select Option A or C, mistakenly believing Cloud Run has a native authentication toggle or that IP-based firewall rules can handle user-level browser SSO without additional identity providers.

Community Discussion (3 comments)

Mr_MIXER007 👍 2 Selected: D
The correct answer is D. Activate Identity-Aware Proxy (IAP) on the Application Load Balancer backend. Assign the role of IAP-secured Web App User to the group of privileged users. Here's why: IAP for Authentication and Authorization: IAP provides a centralized way to control access to your Cloud Run service, ensuring that only authenticated users can reach it. It integrates seamlessly with Cloud Identity for user management and supports single sign-on (SSO) for a smooth user experience. Role-Based Access Control: By assigning the IAP-secured Web App User role to the group of privileged users, you can precisely control who has access to the application.
1e22522 👍 1 Selected: D
should be D
yokoyan 👍 1 Selected: D
I think it's D.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Identity-Aware Proxy (IAP) acts as a reverse proxy that intercepts HTTP/HTTPS requests before they reach the Cloud Run service. It handles user authentication against Google Cloud Identity, enabling seamless browser-based single sign-on, and enforces authorization using the specific IAP-secured Web App User IAM role. This architecture perfectly satisfies the requirement to restrict access to designated organizational users while maintaining internet exposure via the Application Load Balancer.

Why the Other Options Are Wrong

Option A incorrectly assumes Cloud Run includes a built-in authentication switch; it actually delegates interactive web authentication to external proxies like IAP. Option B assigns the Cloud Run User role, which grants management permissions rather than execution or access rights, providing zero authentication layer. Option C restricts traffic at the network layer using static IP whitelisting, which fails to authenticate individual users and contradicts the stated internet-facing ALB design.

Community Comment Notes

Community consensus strongly favors this option, with multiple learners noting that IAP provides centralized access control and integrates natively with Google Identity. As one contributor summarized, this setup is the standard Google-recommended pattern for securing web workloads behind load balancers. The unanimous vote distribution confirms that test-takers recognize IAP as the definitive solution for browser SSO scenarios.

Official Reference

Exam Strategy

When a question specifies browser access with single sign-on for an internet-facing workload, immediately look for a managed identity gateway like IAP. Avoid options that rely on native service toggles or static IP restrictions when user-level authentication and session management are explicitly required.

Frequently Asked Questions

Why isn't Cloud Run Invoker used for browser access?

Cloud Run Invoker grants permission to invoke the service programmatically or via service accounts, not for interactive browser sessions requiring SSO.

Can firewall rules replace IAP for user authentication?

No, firewall rules filter traffic by IP address only and cannot authenticate individual users or enforce single sign-on in a web browser.

Related Analysis

← Back to PCSE Study Guide