Google PCA Design for security and compliance Practice Question
A company is designing a VPC Service Controls perimeter to protect data stored in Google Cloud. They need to allow access from their on-premises network via a Cloud VPN tunnel while blocking all internet-based access. What is the most secure and manageable approach?
⚠ Common exam trap
It's easy for candidates to confuse network-level controls (firewall rules, Private Google Access) with service-level perimeter controls, mistakenly believing that blocking traffic at the VPC level is sufficient to protect Google-managed APIs that are accessed via external endpoints.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a VPC Service Controls perimeter and create an access level that includes the on-premises CIDR range.
VPC Service Controls (VPC SC) is the only Google Cloud-native mechanism that can create a security perimeter around managed services (like Cloud Storage, BigQuery) and restrict access based on an access level that includes the on-premises CIDR range. This ensures that only traffic originating from the on-premises network (via the Cloud VPN tunnel) is allowed, while all internet-based access is blocked, even if the request uses valid credentials. Firewall rules alone cannot restrict access to Google-managed APIs, and Private Google Access does not enforce a perimeter around services.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure firewall rules to only allow traffic from the on-premises CIDR to the VPC.
Why it's wrong here
Firewall rules filter packets at the VPC network layer but do not govern VPC Service Controls, which enforces service perimeters independently of network rules; on-premises VPN traffic still needs an access level. It is tempting because CIDR-scoped rules genuinely restrict which source networks can reach resources.
- ✗
Use Cloud VPN and Private Google Access to allow on-premises access without public IPs.
Why it's wrong here
Private Google Access only lets VM instances reach Google APIs without external IPs; it does not authorise on-premises traffic through the VPC Service Controls perimeter, so VPN-originated requests are still blocked. It is tempting because it removes public IP exposure for private-network access to Google services.
- ✓
Configure a VPC Service Controls perimeter and create an access level that includes the on-premises CIDR range.
Why this is correct
An access level containing the on-premises CIDR range permits traffic arriving through the Cloud VPN tunnel while denying internet-originated requests. This satisfies both the on-premises access requirement and the block-all-internet constraint within one manageable perimeter.
- ✗
Use Cloud IAP (Identity-Aware Proxy) to restrict access based on identity and context.
Why it's wrong here
IAP governs user and application access to web resources by identity and context; it does not admit on-premises VPN traffic into a VPC Service Controls perimeter, which requires an access level or ingress rule. It is tempting because identity-based access control genuinely secures internet-facing apps.
Visual reference
Go deeper
Related to this question
Learn chapter
Virtual Private Cloud (VPC) Networking Basics
Key term
BigQuery
BigQuery is a fully managed, serverless data warehouse on Google Cloud that lets you run fast SQL queries on massive datasets without managing any infrastructure.
Key term
VPC
A Virtual Private Cloud (VPC) is a logically isolated section of a cloud provider's network where you can launch and manage resources like servers and databases with complete control over IP addressing, subnets, route tables, and security.
About these practice questions
Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.