Courseiva
easyMultiple Choice

Google ACE Deploying a GKE cluster in a new VPC Practice Question

A company is deploying a GKE cluster in a new VPC. The cluster nodes need to communicate with a Cloud SQL instance that has a private IP address. The company wants to minimize data transfer costs and avoid using public IPs. What is the most cost-effective configuration?

⚠ Common exam trap

The trap here is assuming that public nodes with whitelisting or VPN are sufficient, but they incur higher costs and are less secure; candidates might overlook Private Service Access as the native, cost-effective solution for private connectivity to Cloud SQL.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a VPC-native cluster with private nodes and configure Private Service Access for Cloud SQL.

Creating a VPC-native cluster with private nodes and configuring Private Service Access for Cloud SQL is the most cost-effective configuration because it keeps all traffic within the private network, avoids public IPs, and minimizes data transfer costs. Private Service Access allows direct private connectivity between the GKE cluster and Cloud SQL without additional network components.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a VPC-native cluster with private nodes and configure Private Service Access for Cloud SQL.

    Why this is correct

    A VPC-native cluster with private nodes keeps pod and node traffic on internal addresses, and Private Service Access reaches Cloud SQL's private IP over the same VPC peering, avoiding public IPs and egress charges. This satisfies the cost and no-public-IP constraints.

  • ✗

    Create a cluster with public nodes and set up a Cloud VPN tunnel to Cloud SQL.

    Why it's wrong here

    A Cloud VPN tunnel terminates at a VPC network, not at a Cloud SQL private IP, so it cannot provide the node-to-database path; it also adds tunnel and egress costs. Cloud VPN suits connecting on-premises networks or peer VPCs, not intra-VPC access to a private Cloud SQL instance.

  • ✗

    Create a VPC-native cluster with public nodes and whitelist the node IPs in Cloud SQL authorized networks.

    Why it's wrong here

    Authorised networks apply only to Cloud SQL public IP connectivity, so nodes would still need public addresses and internet egress, contradicting the requirement. Whitelisting suits external clients reaching a public IP; private-IP Cloud SQL requires VPC-native routing within the same VPC.

  • ✗

    Create a cluster with public nodes and use Cloud NAT for outbound traffic.

    Why it's wrong here

    Public nodes plus Cloud NAT still require public IPs on nodes and egress through NAT, incurring charges and violating the no-public-IP requirement. Cloud NAT is designed for outbound internet access from private instances, not for reaching a Private Service Connect or private-IP Cloud SQL endpoint.

Go deeper

Related to this question

About these practice questions

One of 775 original ACE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.