easyMultiple Choice
Google ACE Deploying a GKE cluster in a new VPC Practice Question
A company is deploying a GKE cluster in a new VPC. The cluster nodes need to communicate with a Cloud SQL instance that has a private IP address. The company wants to minimize data transfer costs and avoid using public IPs. What is the most cost-effective configuration?
⚠ Common exam trap
The trap here is assuming that public nodes with whitelisting or VPN are sufficient, but they incur higher costs and are less secure; candidates might overlook Private Service Access as the native, cost-effective solution for private connectivity to Cloud SQL.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a VPC-native cluster with private nodes and configure Private Service Access for Cloud SQL.
Creating a VPC-native cluster with private nodes and configuring Private Service Access for Cloud SQL is the most cost-effective configuration because it keeps all traffic within the private network, avoids public IPs, and minimizes data transfer costs. Private Service Access allows direct private connectivity between the GKE cluster and Cloud SQL without additional network components.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a VPC-native cluster with private nodes and configure Private Service Access for Cloud SQL.
Why this is correct
A VPC-native cluster with private nodes keeps pod and node traffic on internal addresses, and Private Service Access reaches Cloud SQL's private IP over the same VPC peering, avoiding public IPs and egress charges. This satisfies the cost and no-public-IP constraints.
- ✗
Create a cluster with public nodes and set up a Cloud VPN tunnel to Cloud SQL.
Why it's wrong here
A Cloud VPN tunnel terminates at a VPC network, not at a Cloud SQL private IP, so it cannot provide the node-to-database path; it also adds tunnel and egress costs. Cloud VPN suits connecting on-premises networks or peer VPCs, not intra-VPC access to a private Cloud SQL instance.
- ✗
Create a VPC-native cluster with public nodes and whitelist the node IPs in Cloud SQL authorized networks.
Why it's wrong here
Authorised networks apply only to Cloud SQL public IP connectivity, so nodes would still need public addresses and internet egress, contradicting the requirement. Whitelisting suits external clients reaching a public IP; private-IP Cloud SQL requires VPC-native routing within the same VPC.
- ✗
Create a cluster with public nodes and use Cloud NAT for outbound traffic.
Why it's wrong here
Public nodes plus Cloud NAT still require public IPs on nodes and egress through NAT, incurring charges and violating the no-public-IP requirement. Cloud NAT is designed for outbound internet access from private instances, not for reaching a Private Service Connect or private-IP Cloud SQL endpoint.
Go deeper
Related to this question
Learn chapter
VPC Service Controls
Key term
Private IP address
A private IP address is a non-internet-routable address used within a local network to identify devices and allow them to communicate with each other without direct exposure to the public internet.
Key term
VPC
A Virtual Private Cloud (VPC) is a logically isolated section of a cloud provider's network where you can launch and manage resources like servers and databases with complete control over IP addressing, subnets, route tables, and security.
About these practice questions
One of 775 original ACE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.