Courseiva

Google PCA Manage implementation of cloud architecture Practice Question

A company is using Cloud NAT to allow private instances to access the internet. They notice that outbound connections are failing intermittently. What is the most likely cause?

⚠ Common exam trap

Candidates often confuse intermittent failures with firewall misconfigurations or DNS issues, but the key clue is 'intermittent'—which points to a resource exhaustion problem like port capacity, not a static policy or configuration error.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The number of concurrent connections exceeds the Cloud NAT source port capacity for the assigned NAT IPs.

Cloud NAT uses source network address translation (SNAT) to map private instance IPs to a single public IP address. Each NAT IP has a limited pool of source ports (typically 64,512 per IP for TCP/UDP). When concurrent connections exceed this capacity, new outbound connections are dropped, causing intermittent failures. This is the most likely cause given the symptom of intermittent failures.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The private instances are using the wrong DNS server.

    Why it's wrong here

    DNS resolution failures produce name-resolution errors, not intermittent connection failures; Cloud NAT forwards traffic by IP regardless of the resolver used. It is tempting because DNS misconfiguration is a frequent cause of connectivity issues, and would be correct if instances could not resolve external hostnames at all.

  • ✗

    The VPC firewall rules are blocking egress traffic.

    Why it's wrong here

    If blocked consistently, not intermittently.

  • ✗

    Cloud NAT does not support TCP connections.

    Why it's wrong here

    Cloud NAT explicitly supports TCP, UDP and ICMP, so a blanket lack of TCP support is factually false and cannot explain the symptom. It is tempting because protocol mismatches do cause failures, and would be correct if the NAT gateway were configured to translate only a subset of protocols.

  • ✓

    The number of concurrent connections exceeds the Cloud NAT source port capacity for the assigned NAT IPs.

    Why this is correct

    Cloud NAT allocates a finite pool of source ports per NAT IP address, and each connection consumes one tuple. When concurrent outbound connections exceed that capacity, new connections cannot be translated and fail intermittently, matching the reported symptom.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.