Courseiva

Google ACE Configuring Access and Security Practice Question

A company has multiple VPC networks in their project. They want Compute Engine instances in one VPC to communicate with instances in another VPC using internal IP addresses. Which feature should they use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VPC Network Peering

VPC Peering allows connectivity between two VPC networks using internal IPs. VPN is for on-premises connectivity. Cloud NAT is for outbound internet access. Firewall rules control traffic but do not enable routing between VPCs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cloud NAT

    Why it's wrong here

    Cloud NAT is a managed network address translation service that enables private instances to initiate outbound connections to the internet, but it does not route traffic between VPC networks. It operates only on outgoing traffic and never allows inbound connections from another VPC to your private instances. Since the goal is VPC-to-VPC communication, Cloud NAT cannot provide the required internal connectivity; it is solely an egress mechanism for internet access.

  • ✓

    VPC Network Peering

    Why this is correct

    VPC Network Peering directly connects two VPC networks over Google's private backbone, allowing instances in each network to communicate using internal RFC 1918 addresses without needing public IPs or a VPN. It is the recommended method for inter-VPC connectivity because it offers low latency, no bandwidth restrictions, and no single point of failure. Peering works across projects and organizations, and it automatically exchanges routes for all subnets in the peered networks, so it fully satisfies the requirement to connect multiple VPC networks.

  • ✗

    Cloud VPN

    Why it's wrong here

    Cloud VPN is an IPsec VPN service primarily designed to connect an on-premises network or another cloud network to a VPC, not to directly interconnect two VPCs. While you could use a VPN tunnel between two VPCs by configuring custom routing and gateway IPs, that approach introduces extra latency, public IP exposure, and operational complexity compared to native peering. Because the question asks for a straightforward VPC-to-VPC connection, Cloud VPN is not the appropriate or simplest solution.

  • ✗

    Firewall rules

    Why it's wrong here

    Firewall rules in a VPC are stateful filters that control which packets are allowed or denied based on source/destination IP, port, and protocol, but they do not create any routing path or network link between VPCs. Even if firewall rules are permissive, traffic still cannot flow from one VPC to another without a connectivity mechanism like VPC peering, VPN, or Cloud Interconnect. Therefore, firewall rules can only govern traffic after a path exists; they cannot alone connect multiple VPC networks.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This ACE question is part of Courseiva's 775-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.