Courseiva

Google PCA Manage and provision cloud infrastructure Practice Question

A company runs a service on Cloud Run that needs to access a Cloud SQL instance via private IP. Both are in the same VPC network. The service cannot connect to the database. What is the most likely cause?

⚠ Common exam trap

Google Cloud often tests the misconception that being in the same VPC network automatically grants connectivity, but serverless services like Cloud Run require an explicit Serverless VPC Access connector to route traffic into the VPC.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cloud Run needs a Serverless VPC Access connector.

Cloud Run services run in a Google-managed environment and cannot directly reach resources on a VPC network via private IP. A Serverless VPC Access connector is required to bridge the serverless environment to the VPC, enabling private IP connectivity to Cloud SQL. Without this connector, the Cloud Run service cannot route traffic to the Cloud SQL private IP, even if both are in the same VPC network.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cloud Run must be deployed in the same zone as Cloud SQL.

    Why it's wrong here

    Cloud Run is regional and serverless; zone co-location with Cloud SQL is neither configurable nor required for private IP reachability. Zone affinity is tempting because zonal placement matters for Compute Engine latency, and would be relevant if the workload ran on zonal VMs sharing a subnet.

  • ✗

    The IAM permissions for Cloud Run to access Cloud SQL are missing.

    Why it's wrong here

    Missing IAM permissions produce an authentication or authorisation error from Cloud SQL, not a connection failure, so they cannot explain unreachable private IP connectivity. IAM roles are tempting because Cloud SQL access genuinely requires them, and they would be the answer if the service authenticated but were denied.

  • ✗

    A firewall rule is blocking traffic.

    Why it's wrong here

    Cloud Run egress to a same-VPC Cloud SQL private IP traverses Serverless VPC Access, not standard VPC firewall rules; the connector's subnet and routes govern reachability. Firewall rules are tempting because they commonly block traffic between Compute Engine instances, where they would be the correct place to investigate.

  • ✓

    Cloud Run needs a Serverless VPC Access connector.

    Why this is correct

    Cloud Run egresses through a shared serverless environment, so it cannot reach a private IP inside the VPC without a Serverless VPC Access connector. That connector routes traffic into the VPC, resolving the connection failure.

  • ✗

    The Cloud SQL instance needs a public IP assigned.

    Why it's wrong here

    Assigning a public IP contradicts the private-IP requirement and does not repair the private path; the instance already has a private address in the shared VPC. Public IPs are tempting because they bypass connector routing entirely, and would be correct if the design permitted public egress instead of private connectivity.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.