mediumMultiple Choice
Google ACE Practice Question: Your company runs a critical web application on…
Your company runs a critical web application on Google Kubernetes Engine (GKE) with a regional cluster. The application uses a Cloud SQL instance for database. Recently, users have been experiencing intermittent connection timeouts. The application logs show database connection errors, but the Cloud SQL instance's CPU and memory usage are low. The GKE cluster and Cloud SQL are in the same region. You notice that the Cloud SQL instance is configured with a private IP address. What is the most likely cause of the timeouts?
⚠ Common exam trap
Do not assume that Cloud SQL private IP requires a Private Service Connect endpoint. The standard mechanism is Private Services Access (VPC peering via Service Networking); Private Service Connect is optional. Also, same-region placement does not automatically make the private IP reachable.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The GKE cluster's nodes are in a different VPC subnet than the Cloud SQL instance.
Cloud SQL private IP connectivity is provided by Private Services Access, which creates a VPC peering connection to the Service Networking API. Private Service Connect is an alternative, not a requirement. If the GKE nodes are in a different VPC network/subnet than the Cloud SQL private IP allocation, they do not have a route to that private IP, so connections from the application time out even though the Cloud SQL instance itself is healthy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Cloud SQL instance is not configured with automatic failover.
Why it's wrong here
Automatic failover addresses availability, not intermittent connection errors.
- ✗
The Cloud SQL instance's connection pool size is too small.
Why it's wrong here
A small connection pool would cause errors under load, but database load is low.
- ✗
The GKE cluster is not using a Private Service Connect endpoint to reach Cloud SQL.
Why it's wrong here
Private Service Connect is an alternative private connectivity method, not a requirement for Cloud SQL private IP. The standard method is VPC peering through Service Networking, so missing a PSC endpoint is not the most likely cause.
- ✓
The GKE cluster's nodes are in a different VPC subnet than the Cloud SQL instance.
Why this is correct
If the GKE cluster nodes are in a different VPC network/subnet than the Cloud SQL private IP allocation, they lack a route to the private IP range, causing intermittent connection timeouts.
Visual reference
Go deeper
Related to this question
Learn chapter
Google Cloud Platform Overview
Key term
IP address
An IP address is a unique numerical label assigned to each device connected to a computer network that uses the Internet Protocol for communication.
Key term
Anthos
Anthos is a Google Cloud platform that lets you run applications consistently across different computing environments, like on-premises data centers and multiple public clouds.
About these practice questions
Courseiva writes every ACE question from scratch — 775 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.