Courseiva

Cloud Digital Leader Google Cloud Products and Services Practice Question

A team is using Cloud Build to build container images and push them to Artifact Registry. The build process involves sensitive dependencies that should not be exposed to the internet. The team wants to ensure that all builds execute on a private network without public IP addresses. What should the team configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a private pool in Cloud Build

Cloud Build supports private pools that provide workers in a customer-managed VPC network, allowing builds to run without public IP addresses and access internal resources. Connecting the project to a shared VPC only enables network access but workers still have public IPs unless private pools are used. Using Artifact Registry VPC-SC perimeters helps secure the registry but not the build workers. Cloud NAT provides outbound internet but does not remove public IPs from workers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set up Cloud NAT for the Cloud Build workers

    Why it's wrong here

    Cloud NAT provides outbound internet access to private VPC instances by translating their private IPs to a public IP for egress. However, Cloud Build's default worker pool instances still retain their own public IPs on their network interfaces; NAT does not remove or mask those inbound-facing addresses. Since the requirement is to eliminate public IP exposure entirely, NAT only addresses outbound connectivity, not the inbound attachment of public IPs to the workers.

  • ✗

    Configure Artifact Registry with VPC Service Controls

    Why it's wrong here

    VPC Service Controls (VPC-SC) creates security perimeters around Google Cloud services like Artifact Registry, preventing data exfiltration and restricting access from untrusted networks. This protects the registry, but it has no effect on the network configuration of Cloud Build workers—they remain in the default pool with public IPs. VPC-SC does not move worker instances into your VPC or strip their public IPs, so it fails the core requirement of private, IP-free build execution.

  • ✓

    Use a private pool in Cloud Build

    Why this is correct

    A private pool in Cloud Build runs workers in a VPC network that you control, and these worker instances are provisioned without public IP addresses. Because they are internal-only, builds can pull source code from private repositories and push images to Artifact Registry without ever traversing the public internet or exposing the workers. This directly satisfies the requirement to remove public IPs while still allowing secure access to private resources.

  • ✗

    Connect the Cloud Build service account to a shared VPC

    Why it's wrong here

    Connecting the Cloud Build service account to a shared VPC grants the service account IAM roles and access to VPC resources, such as subnets or firewall rules. However, this does not alter the placement of the worker instances themselves—they are still created in Cloud Build's default network, which uses public IPs. The service account is an identity, not a network configuration object, so it cannot cause workers to run privately or eliminate their public IP assignments.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This GCDL question is part of Courseiva's 848-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.