Courseiva
mediumMultiple Choice

Google ACE Practice Question: A Compute Engine VM with only a private IP…

A Compute Engine VM with only a private IP address needs to download software updates from the internet (apt-get update). What must be configured in the VPC to enable outbound internet access for private VMs?

⚠ Common exam trap

Google Cloud often tests the distinction between Private Google Access (for Google APIs only) and Cloud NAT (for general internet access), leading candidates to mistakenly choose Private Google Access when the requirement is for outbound internet access to non-Google endpoints.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure Cloud NAT on the VPC's Cloud Router for the subnet

Cloud NAT (Network Address Translation) allows private VMs without external IP addresses to initiate outbound connections to the internet. It translates the VM's private IP to a public IP managed by Cloud NAT, enabling apt-get update to reach external repositories. This is the correct and scalable solution for outbound-only internet access from private instances.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Private Google Access on the subnet

    Why it's wrong here

    Private Google Access enables instances with internal IPs to reach Google APIs and services (e.g., Cloud Storage, BigQuery) over the Google network, not the public internet. External package repositories like Debian mirrors or PyPI are not part of Google's API endpoints, so PGA does not handle that traffic. Without Cloud NAT or an external IP, requests to those repositories will still time out.

  • ✓

    Configure Cloud NAT on the VPC's Cloud Router for the subnet

    Why this is correct

    Configuring Cloud NAT on the VPC's Cloud Router for the subnet is correct because it provides source network address translation for instances with private IPs. The NAT gateway maps the private source addresses to a shared public IP, allowing outbound internet connections while keeping the instances themselves unreachable from the outside. This makes apt-get, pip, and similar package managers work without assigning per-VM external IPs.

  • ✗

    Add an external IP address to the VM temporarily for the update, then remove it

    Why it's wrong here

    Temporarily attaching an external IP to the VM is a workaround but introduces unnecessary security exposure; the VM becomes directly reachable from the public internet, expanding the attack surface during the update window. It also requires manual intervention and, if the IP is ephemeral, may change on subsequent operations, creating operational overhead. Cloud NAT achieves the same outbound access without per-VM public exposure.

  • ✗

    Create a VPC firewall rule allowing egress to 0.0.0.0/0 on port 80 and 443

    Why it's wrong here

    A VPC firewall egress rule permitting 0.0.0.0/0 on ports 80 and 443 only removes the firewall block; it does not provide a routable public source IP. Instances with only private/internal IPs cannot send traffic to the internet because their packets are not translated and would be dropped by the VPC's routing. Outbound connectivity to the internet requires both firewall rules and Cloud NAT.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This ACE question is part of Courseiva's 775-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.