Google PCA Manage implementation of cloud architecture Practice Question
A company runs multiple microservices on Cloud Run. Each service uses a Serverless VPC Access connector to connect to a shared Cloud Memorystore for Redis instance (standard tier) in a VPC network. The Redis instance is configured with a firewall rule that allows TCP connections on port 6379 from the VPC connector's subnet (10.8.0.0/28). After a recent code update, the order-service fails to connect to Redis, while the user-service continues to work. The error logs in order-service show 'connection refused'. The engineer verifies that both services use the same VPC connector, the same Redis instance IP, and the same service account. The VPC connector's metrics show no errors. What is the most likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The order-service code now attempts to connect to Redis on port 6380.
The order-service successfully connects to the same Redis instance before the code update. After the update, it fails with 'connection refused', while the user-service still works. Since both services share the same networking configuration and the firewall only allows port 6379, the most likely cause is that the order-service code now attempts to connect on a different port (e.g., 6380) that is not allowed by the firewall. Other options would affect both services or are inconsistent with the symptoms.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The order-service is deployed in a different region than the Redis instance.
Why it's wrong here
A cross-region deployment would not produce "connection refused" on port 6379, since the connector's subnet firewall rule and routing remain valid regardless of the service's region. It is tempting because Serverless VPC Access connectors are regional resources, so region mismatch is a genuine failure mode when a service cannot reach a connector at all.
- ✓
The order-service code now attempts to connect to Redis on port 6380.
Why this is correct
Redis standard tier listens on TCP 6379, so a firewall rule permitting only that port would refuse a connection on 6380. The unchanged user-service confirms the connector and instance are healthy, isolating the port change in order-service code.
- ✗
The VPC connector is out of memory.
Why it's wrong here
A memory-exhausted connector drops or queues packets, producing timeouts rather than the immediate TCP RST that "connection refused" indicates, and its metrics would show failures — yet the stem reports none, and user-service shares the same connector. Connector memory sizing matters when scaling many concurrent connections across services, not for a single service's refused connection.
- ✗
The Redis instance has reached its maximum number of connections.
Why it's wrong here
A connection-limit exhaustion would produce errors across every client sharing the instance, yet user-service still connects through the same connector and IP. Redis maxclients rejections also surface as "max number of clients reached", not "connection refused". This cause fits scenarios where many clients saturate a fixed connection ceiling, not one failing service.
Visual reference
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
Learn chapter
Deployment Manager and Infrastructure as Code
Key term
Software-defined Wide Area Network
A Software-defined Wide Area Network (SD-WAN) is a virtual network architecture that uses software to manage and optimize the connections between branch offices and data centers across a wide geographic area.
Key term
Service account
A service account is a special type of account used by an application or a virtual machine, rather than a human user, to authenticate and interact with cloud services and APIs securely.
About these practice questions
This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.