Google PCA Manage and provision cloud infrastructure Practice Question
A company runs a service on Cloud Run that needs to access a Cloud SQL instance via private IP. Both are in the same VPC network. The service cannot connect to the database. What is the most likely cause?
⚠ Common exam trap
Google Cloud often tests the misconception that being in the same VPC network automatically grants connectivity, but serverless services like Cloud Run require an explicit Serverless VPC Access connector to route traffic into the VPC.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud Run needs a Serverless VPC Access connector.
Cloud Run services run in a Google-managed environment and cannot directly reach resources on a VPC network via private IP. A Serverless VPC Access connector is required to bridge the serverless environment to the VPC, enabling private IP connectivity to Cloud SQL. Without this connector, the Cloud Run service cannot route traffic to the Cloud SQL private IP, even if both are in the same VPC network.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cloud Run must be deployed in the same zone as Cloud SQL.
Why it's wrong here
Cloud Run is regional and serverless; zone co-location with Cloud SQL is neither configurable nor required for private IP reachability. Zone affinity is tempting because zonal placement matters for Compute Engine latency, and would be relevant if the workload ran on zonal VMs sharing a subnet.
- ✗
The IAM permissions for Cloud Run to access Cloud SQL are missing.
Why it's wrong here
Missing IAM permissions produce an authentication or authorisation error from Cloud SQL, not a connection failure, so they cannot explain unreachable private IP connectivity. IAM roles are tempting because Cloud SQL access genuinely requires them, and they would be the answer if the service authenticated but were denied.
- ✗
A firewall rule is blocking traffic.
Why it's wrong here
Cloud Run egress to a same-VPC Cloud SQL private IP traverses Serverless VPC Access, not standard VPC firewall rules; the connector's subnet and routes govern reachability. Firewall rules are tempting because they commonly block traffic between Compute Engine instances, where they would be the correct place to investigate.
- ✓
Cloud Run needs a Serverless VPC Access connector.
Why this is correct
Cloud Run egresses through a shared serverless environment, so it cannot reach a private IP inside the VPC without a Serverless VPC Access connector. That connector routes traffic into the VPC, resolving the connection failure.
- ✗
The Cloud SQL instance needs a public IP assigned.
Why it's wrong here
Assigning a public IP contradicts the private-IP requirement and does not repair the private path; the instance already has a private address in the shared VPC. Public IPs are tempting because they bypass connector routing entirely, and would be correct if the design permitted public egress instead of private connectivity.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
Learn chapter
Identity and Access Management (IAM)
Key term
Route
A route is a path that data takes through a network from one device or network to another, determined by routing protocols and configured rules.
Key term
Cloud SQL
Cloud SQL is a fully managed relational database service that lets you set up, maintain, and scale SQL databases (like MySQL, PostgreSQL, and SQL Server) in the cloud without managing the underlying infrastructure.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.