Cloud Digital Leader Google Cloud Products and Services Practice Question
A team is using Cloud Build to build container images and push them to Artifact Registry. The build process involves sensitive dependencies that should not be exposed to the internet. The team wants to ensure that all builds execute on a private network without public IP addresses. What should the team configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a private pool in Cloud Build
Cloud Build supports private pools that provide workers in a customer-managed VPC network, allowing builds to run without public IP addresses and access internal resources. Connecting the project to a shared VPC only enables network access but workers still have public IPs unless private pools are used. Using Artifact Registry VPC-SC perimeters helps secure the registry but not the build workers. Cloud NAT provides outbound internet but does not remove public IPs from workers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set up Cloud NAT for the Cloud Build workers
Why it's wrong here
Cloud NAT provides outbound internet access to private VPC instances by translating their private IPs to a public IP for egress. However, Cloud Build's default worker pool instances still retain their own public IPs on their network interfaces; NAT does not remove or mask those inbound-facing addresses. Since the requirement is to eliminate public IP exposure entirely, NAT only addresses outbound connectivity, not the inbound attachment of public IPs to the workers.
- ✗
Configure Artifact Registry with VPC Service Controls
Why it's wrong here
VPC Service Controls (VPC-SC) creates security perimeters around Google Cloud services like Artifact Registry, preventing data exfiltration and restricting access from untrusted networks. This protects the registry, but it has no effect on the network configuration of Cloud Build workers—they remain in the default pool with public IPs. VPC-SC does not move worker instances into your VPC or strip their public IPs, so it fails the core requirement of private, IP-free build execution.
- ✓
Use a private pool in Cloud Build
Why this is correct
A private pool in Cloud Build runs workers in a VPC network that you control, and these worker instances are provisioned without public IP addresses. Because they are internal-only, builds can pull source code from private repositories and push images to Artifact Registry without ever traversing the public internet or exposing the workers. This directly satisfies the requirement to remove public IPs while still allowing secure access to private resources.
- ✗
Connect the Cloud Build service account to a shared VPC
Why it's wrong here
Connecting the Cloud Build service account to a shared VPC grants the service account IAM roles and access to VPC resources, such as subnets or firewall rules. However, this does not alter the placement of the worker instances themselves—they are still created in Cloud Build's default network, which uses public IPs. The service account is an identity, not a network configuration object, so it cannot cause workers to run privately or eliminate their public IP assignments.
Visual reference
Go deeper
Related to this question
Learn chapter
GCP Network: VPC, Subnets, and Firewalls
Key term
Container
A container is a lightweight, standalone software package that includes everything needed to run an application, such as code, runtime, system tools, and libraries.
Key term
Artifact Registry
Artifact Registry is a managed service for storing, managing, and securing container images and other software packages in a centralized repository.
About these practice questions
This GCDL question is part of Courseiva's 848-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.