Google PCA Manage and provision cloud infrastructure Practice Question
A financial services company needs to ensure that all outbound traffic from its Compute Engine instances to the internet goes through a dedicated IP address for allowlisting by a partner. The instances are in a private subnet with no external IP addresses. The company wants to minimize management overhead and avoid single points of failure. Which solution should the architect implement?
⚠ Common exam trap
The trap here is thinking that a self-managed NAT instance or VPN is needed for a dedicated egress IP, when Cloud NAT with manual IP allocation provides this as a managed service.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a Cloud NAT gateway with a manual IP address allocation and attach it to the VPC network in the region where the instances reside.
Cloud NAT with manual IP allocation is the correct solution because it provides a managed, regional service that uses reserved external IP addresses for outbound traffic from private instances. It scales automatically, has no single point of failure, and requires minimal operational effort, directly satisfying the partner allowlisting requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Assign external IP addresses to all instances and use Cloud DNS to map them to a single hostname for the partner.
Why it's wrong here
Assigning external IPs to each instance means outbound traffic uses many different source IP addresses, which cannot be allowlisted as a single dedicated IP. Cloud DNS does not change the source IP of outbound connections. This approach fails the core requirement of a single dedicated egress IP.
- ✓
Configure a Cloud NAT gateway with a manual IP address allocation and attach it to the VPC network in the region where the instances reside.
Why this is correct
Cloud NAT with manual IP allocation lets you reserve specific external IP addresses that are used for all outbound traffic from the private instances. It is a regional, managed service that scales automatically and avoids single points of failure, meeting the allowlisting requirement with minimal management overhead.
- ✗
Create a VPN tunnel to the partner's network and route all internet-bound traffic through the partner's gateway.
Why it's wrong here
A VPN tunnel to the partner would route traffic through the partner's network, but it does not provide a dedicated Google Cloud IP for allowlisting and adds complexity and dependency on the partner's infrastructure. It also does not scale automatically and may introduce latency, failing the management overhead and availability goals.
- ✗
Deploy a third-party firewall appliance on a Compute Engine instance with an external IP and route all outbound traffic through it using a custom route.
Why it's wrong here
A self-managed firewall appliance introduces a single point of failure and requires significant operational overhead for high availability, patching, and scaling. While it can provide a dedicated IP, it does not meet the requirement to minimize management overhead and avoid single points of failure as effectively as a managed service.
Visual reference
Go deeper
Related to this question
Learn chapter
Virtual Private Cloud (VPC) Networking Basics
Key term
Compute Engine
Compute Engine is Google Cloud's Infrastructure-as-a-Service (IaaS) offering that lets you create and run virtual machines on Google's infrastructure.
Key term
Regional
Regional refers to a deployment strategy where cloud resources are distributed across multiple geographic areas to improve availability, reduce latency, and meet compliance requirements.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.