Google PCA Design and plan a cloud solution architecture Practice Question
A company is designing a hybrid cloud architecture where on-premises applications need to access data stored in a Cloud Storage bucket. The company requires that traffic between on-premises and Google Cloud does not traverse the public internet and must be encrypted. They also need dedicated bandwidth. Which Google Cloud service should the solutions architect use?
⚠ Common exam trap
Test-takers frequently confuse Cloud VPN, which uses the public internet, with Cloud Interconnect, which provides a private dedicated connection, and overlooking that Dedicated Interconnect can also support encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud Interconnect with Dedicated Interconnect.
Dedicated Interconnect offers a private, dedicated connection between on-premises and Google Cloud, avoiding the public internet and providing consistent bandwidth. It supports encryption through MACsec or higher-layer protocols. This satisfies the requirements for private, encrypted, and dedicated connectivity for accessing Cloud Storage data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
VPC Network Peering between on-premises and Google Cloud.
Why it's wrong here
VPC Network Peering connects two VPC networks within Google Cloud, not on-premises networks. It does not provide connectivity from on-premises to Google Cloud and cannot be used for hybrid architectures. This option is irrelevant to the scenario.
- ✗
Cloud CDN with private origin access.
Why it's wrong here
Cloud CDN caches content at edge locations to reduce latency, but it does not provide private connectivity from on-premises to Google Cloud. It operates over the public internet and is not designed for dedicated bandwidth or private data transfer. This service does not address the hybrid connectivity requirements.
- ✗
Cloud VPN with HA VPN.
Why it's wrong here
HA VPN provides encrypted tunnels over the public internet, which does not meet the requirement to avoid the public internet. While it offers high availability, it lacks dedicated bandwidth and uses the internet for transport. This makes it unsuitable for the scenario's need for private, dedicated connectivity.
- ✓
Cloud Interconnect with Dedicated Interconnect.
Why this is correct
Dedicated Interconnect provides a direct physical connection between on-premises and Google Cloud, bypassing the public internet. It offers dedicated bandwidth and supports encryption via MACsec or application-level encryption. This meets all requirements: private connectivity, dedicated bandwidth, and encryption.
Go deeper
Related to this question
Learn chapter
Cloud Storage: Objects and Buckets
Key term
Hybrid cloud
A hybrid cloud is a computing environment that combines a private cloud (on-premises infrastructure) with one or more public cloud services, allowing data and applications to be shared between them.
Key term
Data
Data is raw, unprocessed information, like numbers, words, or measurements, that can be stored, processed, and analyzed by computers.
About these practice questions
Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.