Courseiva

Google PCA Practice Question: Managing and Provisioning a Solution Infrastructure

A company is migrating a legacy application that uses a file server to GCP. The application requires a shared file system that supports the NFS protocol and can be mounted by multiple Compute Engine instances. The team also needs to use Cloud NAT to allow the instances to download updates. Which TWO services should they use? (Choose 2)

⚠ Common exam trap

The trap is confusing Private Google Access with Cloud NAT — candidates pick Private Google Access for outbound internet, but it only covers Google APIs, while Cloud NAT handles general outbound internet access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cloud NAT

Cloud Filestore (D) is correct because it is GCP's fully managed file storage service that natively supports the NFSv3 protocol and can be mounted simultaneously by multiple Compute Engine instances, which is exactly what the legacy application requires for its shared file system. Cloud NAT (A) is correct because it provides outbound internet access for instances without external IP addresses, allowing them to download updates while remaining unreachable from the internet. Cloud VPN (B) is not appropriate here because it establishes encrypted tunnels to on-premises or other networks, not a shared NFS file system or outbound NAT. Cloud Storage Fuse (C) is not correct because it mounts Cloud Storage buckets as a local file system via a FUSE adapter, which does not provide a true NFS-protocol shared file system for multiple instances. Private Google Access (E) is not correct because it only enables instances without external IPs to reach Google APIs and services, not general internet downloads, which is what Cloud NAT handles.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Cloud NAT

    Why this is correct

    Cloud NAT provides managed outbound internet connectivity for Compute Engine instances without external IP addresses, letting them download updates. It satisfies the requirement directly and is the correct service pairing alongside the shared NFS file system.

  • ✗

    Cloud VPN

    Why it's wrong here

    Cloud VPN provides encrypted tunnels between networks, not a mountable NFS file system, so it cannot satisfy the shared-storage requirement. It is tempting because Cloud VPN legitimately connects on-premises or VPC networks to GCP, and would be the right choice when extending a corporate network or linking sites over IPsec.

  • ✗

    Cloud Storage Fuse

    Why it's wrong here

    Cloud Storage FUSE presents a GCS bucket as a local mount, but it is a POSIX-translation layer over object storage, not a true shared NFS file system, so it fails the NFS protocol requirement. It tempts because it suits read-heavy workloads needing bucket access from Compute Engine without rewriting code.

  • ✓

    Cloud Filestore

    Why this is correct

    Cloud Filestore delivers a managed NFS file share that multiple Compute Engine instances can mount concurrently, matching the legacy application's shared file server requirement. It satisfies the NFS and multi-instance mounting constraints without self-managed storage.

  • ✗

    Private Google Access

    Why it's wrong here

    Private Google Access lets instances without external IPs reach Google APIs and services, but it cannot serve NFS data to Compute Engine clients. It is tempting because it removes the need for Cloud NAT when accessing Google APIs internally; however, the stem requires Cloud NAT for internet updates, and a shared NFS file system, which Filestore provides.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.