Google PCA Manage implementation of cloud architecture Practice Question
A company is using Cloud NAT to allow private instances to access the internet. They notice that outbound connections are failing intermittently. What is the most likely cause?
⚠ Common exam trap
Candidates often confuse intermittent failures with firewall misconfigurations or DNS issues, but the key clue is 'intermittent'—which points to a resource exhaustion problem like port capacity, not a static policy or configuration error.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The number of concurrent connections exceeds the Cloud NAT source port capacity for the assigned NAT IPs.
Cloud NAT uses source network address translation (SNAT) to map private instance IPs to a single public IP address. Each NAT IP has a limited pool of source ports (typically 64,512 per IP for TCP/UDP). When concurrent connections exceed this capacity, new outbound connections are dropped, causing intermittent failures. This is the most likely cause given the symptom of intermittent failures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The private instances are using the wrong DNS server.
Why it's wrong here
DNS resolution failures produce name-resolution errors, not intermittent connection failures; Cloud NAT forwards traffic by IP regardless of the resolver used. It is tempting because DNS misconfiguration is a frequent cause of connectivity issues, and would be correct if instances could not resolve external hostnames at all.
- ✗
The VPC firewall rules are blocking egress traffic.
Why it's wrong here
If blocked consistently, not intermittently.
- ✗
Cloud NAT does not support TCP connections.
Why it's wrong here
Cloud NAT explicitly supports TCP, UDP and ICMP, so a blanket lack of TCP support is factually false and cannot explain the symptom. It is tempting because protocol mismatches do cause failures, and would be correct if the NAT gateway were configured to translate only a subset of protocols.
- ✓
The number of concurrent connections exceeds the Cloud NAT source port capacity for the assigned NAT IPs.
Why this is correct
Cloud NAT allocates a finite pool of source ports per NAT IP address, and each connection consumes one tuple. When concurrent outbound connections exceed that capacity, new connections cannot be translated and fail intermittently, matching the reported symptom.
Visual reference
Go deeper
Related to this question
Learn chapter
Virtual Machine Instances in Compute Engine
Key term
User Datagram Protocol
User Datagram Protocol (UDP) is a fast, connectionless network protocol that sends data without first checking if the receiver is ready or if the data arrived safely.
Key term
IP address
An IP address is a unique numerical label assigned to each device connected to a computer network that uses the Internet Protocol for communication.
About these practice questions
Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.