Courseiva

Google PCA Manage implementation of cloud architecture Practice Question

A company runs multiple microservices on Cloud Run. Each service uses a Serverless VPC Access connector to connect to a shared Cloud Memorystore for Redis instance (standard tier) in a VPC network. The Redis instance is configured with a firewall rule that allows TCP connections on port 6379 from the VPC connector's subnet (10.8.0.0/28). After a recent code update, the order-service fails to connect to Redis, while the user-service continues to work. The error logs in order-service show 'connection refused'. The engineer verifies that both services use the same VPC connector, the same Redis instance IP, and the same service account. The VPC connector's metrics show no errors. What is the most likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The order-service code now attempts to connect to Redis on port 6380.

The order-service successfully connects to the same Redis instance before the code update. After the update, it fails with 'connection refused', while the user-service still works. Since both services share the same networking configuration and the firewall only allows port 6379, the most likely cause is that the order-service code now attempts to connect on a different port (e.g., 6380) that is not allowed by the firewall. Other options would affect both services or are inconsistent with the symptoms.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The order-service is deployed in a different region than the Redis instance.

    Why it's wrong here

    A cross-region deployment would not produce "connection refused" on port 6379, since the connector's subnet firewall rule and routing remain valid regardless of the service's region. It is tempting because Serverless VPC Access connectors are regional resources, so region mismatch is a genuine failure mode when a service cannot reach a connector at all.

  • ✓

    The order-service code now attempts to connect to Redis on port 6380.

    Why this is correct

    Redis standard tier listens on TCP 6379, so a firewall rule permitting only that port would refuse a connection on 6380. The unchanged user-service confirms the connector and instance are healthy, isolating the port change in order-service code.

  • ✗

    The VPC connector is out of memory.

    Why it's wrong here

    A memory-exhausted connector drops or queues packets, producing timeouts rather than the immediate TCP RST that "connection refused" indicates, and its metrics would show failures — yet the stem reports none, and user-service shares the same connector. Connector memory sizing matters when scaling many concurrent connections across services, not for a single service's refused connection.

  • ✗

    The Redis instance has reached its maximum number of connections.

    Why it's wrong here

    A connection-limit exhaustion would produce errors across every client sharing the instance, yet user-service still connects through the same connector and IP. Redis maxclients rejections also surface as "max number of clients reached", not "connection refused". This cause fits scenarios where many clients saturate a fixed connection ceiling, not one failing service.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

Go deeper

Related to this question

About these practice questions

This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.