Courseiva

Google ACE Configuring Access and Security Practice Question

An engineer wants to create a VPC with a custom subnet mode and then create a subnet with Private Google Access enabled. Which two commands should they use? (Choose TWO.)

⚠ Common exam trap

ACE often tests the distinction between VPC-level and subnet-level settings — candidates pick the subnet create command without the Private Google Access flag, forgetting that the flag is what actually enables the feature.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

gcloud compute networks subnets create my-subnet --network my-vpc --region us-central1 --range 10.0.0.0/24 --enable-private-ip-google-access

Option B is correct because creating a VPC in custom subnet mode requires the command `gcloud compute networks create my-vpc --subnet-mode custom`, which prevents Google Cloud from automatically creating subnets in each region and is the necessary first step for the scenario. Option A is correct because `gcloud compute networks subnets create my-subnet --network my-vpc --region us-central1 --range 10.0.0.0/24 --enable-private-ip-google-access` creates the subnet with the `--enable-private-ip-google-access` flag, which turns on Private Google Access so instances without external IPs can reach Google APIs and services. Option C is incorrect because it creates the subnet without the `--enable-private-ip-google-access` flag, so Private Google Access would remain disabled. Option D is incorrect because it creates a firewall rule for HTTP traffic, which is unrelated to subnet mode or Private Google Access. Option E is incorrect because `--subnet-mode auto` creates an auto mode VPC, which contradicts the requirement for a custom subnet mode VPC.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    gcloud compute networks subnets create my-subnet --network my-vpc --region us-central1 --range 10.0.0.0/24 --enable-private-ip-google-access

    Why this is correct

    This command explicitly creates a subnet in a custom mode VPC (assuming the VPC already exists) and enables Private Google Access, allowing instances in that subnet to reach Google APIs and services through their internal IP addresses without needing a NAT or external IP. In a custom mode VPC, you must create each subnet manually, and this command defines the region and IP range, making it a required step after the VPC is created. Without this flag, the subnet would lack the Private Google Access capability, which is often a prerequisite for workloads that should reach Google services without public IPs.

  • ✓

    gcloud compute networks create my-vpc --subnet-mode custom

    Why this is correct

    This command creates a new VPC network named my-vpc in custom subnet mode, meaning it starts with no subnets and allows you to define subnets with your own IP ranges and regions. Custom mode is the correct choice when you need full control over subnet planning, such as specific CIDR ranges or future IP space management, unlike auto mode which auto-generates subnets in every region. This is the foundational command but it alone does not create any subnets; a subsequent subnet creation command is required.

  • ✗

    gcloud compute networks subnets create my-subnet --network my-vpc --region us-central1 --range 10.0.0.0/24

    Why it's wrong here

    This command is incomplete because it creates a subnet but omits the --enable-private-ip-google-access flag, leaving Private Google Access disabled for that subnet. While it successfully creates an IP range and attaches the subnet to my-vpc, instances in that subnet would need external IP addresses or a Cloud NAT to reach Google APIs, which contradicts the requirement for private access. Therefore, the missing flag makes this option fail the full requirement.

  • ✗

    gcloud compute firewall-rules create allow-http --allow tcp:80

    Why it's wrong here

    This command creates a firewall rule allowing TCP port 80 traffic, but it does not contribute to creating a VPC or a subnet, which is the stated goal. Firewall rules are network-level security controls applied after a network and subnets exist, so running this command alone would fail because the network my-vpc may not even exist yet, and it has no effect on subnet mode. It is irrelevant to the task.

  • ✗

    gcloud compute networks create my-vpc --subnet-mode auto

    Why it's wrong here

    This command creates a VPC in auto subnet mode, where Google automatically creates subnets in every Google Cloud region using a predefined IP range. That is the opposite of custom mode, which starts with no subnets and lets the engineer define them manually, so this command would not satisfy the requirement for a custom subnet mode VPC. It could be corrected by changing --subnet-mode auto to --subnet-mode custom.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Go deeper

Related to this question

About these practice questions

Courseiva writes every ACE question from scratch — 775 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.