Google PCA Practice Question: Managing and Provisioning a Solution Infrastructure
A company is migrating a legacy application that uses a file server to GCP. The application requires a shared file system that supports the NFS protocol and can be mounted by multiple Compute Engine instances. The team also needs to use Cloud NAT to allow the instances to download updates. Which TWO services should they use? (Choose 2)
⚠ Common exam trap
The trap is confusing Private Google Access with Cloud NAT — candidates pick Private Google Access for outbound internet, but it only covers Google APIs, while Cloud NAT handles general outbound internet access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud NAT
Cloud Filestore (D) is correct because it is GCP's fully managed file storage service that natively supports the NFSv3 protocol and can be mounted simultaneously by multiple Compute Engine instances, which is exactly what the legacy application requires for its shared file system. Cloud NAT (A) is correct because it provides outbound internet access for instances without external IP addresses, allowing them to download updates while remaining unreachable from the internet. Cloud VPN (B) is not appropriate here because it establishes encrypted tunnels to on-premises or other networks, not a shared NFS file system or outbound NAT. Cloud Storage Fuse (C) is not correct because it mounts Cloud Storage buckets as a local file system via a FUSE adapter, which does not provide a true NFS-protocol shared file system for multiple instances. Private Google Access (E) is not correct because it only enables instances without external IPs to reach Google APIs and services, not general internet downloads, which is what Cloud NAT handles.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Cloud NAT
Why this is correct
Cloud NAT provides managed outbound internet connectivity for Compute Engine instances without external IP addresses, letting them download updates. It satisfies the requirement directly and is the correct service pairing alongside the shared NFS file system.
- ✗
Cloud VPN
Why it's wrong here
Cloud VPN provides encrypted tunnels between networks, not a mountable NFS file system, so it cannot satisfy the shared-storage requirement. It is tempting because Cloud VPN legitimately connects on-premises or VPC networks to GCP, and would be the right choice when extending a corporate network or linking sites over IPsec.
- ✗
Cloud Storage Fuse
Why it's wrong here
Cloud Storage FUSE presents a GCS bucket as a local mount, but it is a POSIX-translation layer over object storage, not a true shared NFS file system, so it fails the NFS protocol requirement. It tempts because it suits read-heavy workloads needing bucket access from Compute Engine without rewriting code.
- ✓
Cloud Filestore
Why this is correct
Cloud Filestore delivers a managed NFS file share that multiple Compute Engine instances can mount concurrently, matching the legacy application's shared file server requirement. It satisfies the NFS and multi-instance mounting constraints without self-managed storage.
- ✗
Private Google Access
Why it's wrong here
Private Google Access lets instances without external IPs reach Google APIs and services, but it cannot serve NFS data to Compute Engine clients. It is tempting because it removes the need for Cloud NAT when accessing Google APIs internally; however, the stem requires Cloud NAT for internet updates, and a shared NFS file system, which Filestore provides.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
Learn chapter
IAM Policies, Service Accounts, and Auditing
Key term
Cloud NAT
Cloud NAT is a managed network address translation service that allows private cloud resources to initiate outbound internet connections while keeping them unreachable from the internet.
Key term
Compute Engine
Compute Engine is Google Cloud's Infrastructure-as-a-Service (IaaS) offering that lets you create and run virtual machines on Google's infrastructure.
About these practice questions
Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.