Google ACE Planning and Configuring a Cloud Solution Practice Question
A company has a private VPC with instances that have only internal IP addresses. These instances need to download updates from the internet. Which Google Cloud service should they use to provide outbound internet connectivity?
⚠ Common exam trap
The trap is thinking 'internet access requires a public IP'; GCP's design separates egress (Cloud NAT) from ingress (load balancers/public IPs), and candidates often pick the public IP option.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud NAT
Cloud NAT (Network Address Translation) allows instances with only internal IP addresses to initiate outbound connections to the internet without exposing them to inbound traffic. It performs many-to-one IP translation and is the Google-recommended service for egress-only internet access from private VPC subnets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Cloud NAT
Why this is correct
Cloud NAT uses a Cloud Router to provide a managed Network Address Translation service that gives private instances (those with internal IPs only) a secure path to the internet for outbound connections. It maintains stateful sessions so return traffic is allowed, but unsolicited inbound connections are blocked, preserving the private nature of the network.
- ✗
Cloud VPN
Why it's wrong here
Cloud VPN establishes an IPsec tunnel from Google Cloud to an on-premises or other remote network, enabling private, encrypted communication between disparate networks. It does not provide any internet egress capability for VM instances; it only routes traffic to the connected peer network, so instances still lack a path to the public internet.
- ✗
Assign public IP addresses to the instances
Why it's wrong here
Assigning public IP addresses to instances directly enables outbound internet, but it also exposes each instance to inbound traffic from the internet unless restricted by network firewall rules. This contradicts the requirement to keep instances private and could force you to manage per-instance static public IPs, scaling costs and security overhead.
- ✗
Identity-Aware Proxy (IAP)
Why it's wrong here
Identity-Aware Proxy (IAP) is a Google Cloud service that enforces identity-based access control to applications or VMs via OAuth, typically using a secure tunnel for management. It does not function as a general-purpose egress gateway; its tunnel only forwards specific connections to selected resources, not arbitrary outbound traffic from instances to the internet.
Visual reference
Go deeper
Related to this question
Learn chapter
Google Compute Engine
Key term
NAT
NAT (Network Address Translation) is a method that allows multiple devices on a private network to share a single public IP address when accessing the internet.
Key term
Service
A service is a software component or system that performs a specific function and is available to be used by other programs or users over a network.
About these practice questions
One of 775 original ACE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.