Google PCA Design for security and compliance Practice Question
A financial services company runs a multi-tier application on Compute Engine. They need to restrict network access so that only the web tier can communicate with the application tier, and only the application tier can access the database tier. All VMs are in the same VPC network. What is the most secure way to implement this?
⚠ Common exam trap
Test-takers frequently confuse IAM conditions or service accounts with network-layer access control, or they overcomplicate the solution by suggesting separate VPC networks when the simplest and most secure method within a single VPC is using firewall rules with target tags.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use VPC firewall rules with target tags to allow traffic between specific tiers.
VPC firewall rules with target tags allow you to precisely control ingress and egress traffic between VM instances based on their assigned tags. By tagging web tier VMs with a tag like 'web-tier' and application tier VMs with 'app-tier', you can create a firewall rule that allows traffic from 'web-tier' to 'app-tier' on the required port (e.g., TCP 8080) and another rule allowing traffic from 'app-tier' to 'db-tier' on the database port (e.g., TCP 3306). This approach enforces the principle of least privilege within a single VPC network without introducing unnecessary complexity or breaking network isolation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Identity-Aware Proxy (IAP) to manage network access between tiers.
Why it's wrong here
IAP authenticates and authorises user or service access to applications behind it; it does not filter east-west traffic between Compute Engine instances. It is tempting because IAP is the right control for exposing internal web apps to remote users without public IPs, which is a different requirement from tier-to-tier network segmentation.
- ✓
Use VPC firewall rules with target tags to allow traffic between specific tiers.
Why this is correct
VPC firewall rules with target tags apply ingress rules only to VMs carrying the specified tag, so the application tier accepts traffic solely from the web tier's tag and the database tier solely from the application tier, enforcing tier isolation within one VPC network.
- ✗
Create separate VPC networks for each tier and use VPC peering.
Why it's wrong here
Peering links whole networks, so once peered every tier can reach every other tier's instances; it cannot enforce tier-to-tier directionality without additional firewall rules. It is tempting because separate VPC networks genuinely isolate blast radius and suit hard multi-tenant or regulatory separation, but here all tiers already share one VPC.
- ✗
Assign a unique service account to each tier and use IAM conditions to restrict traffic.
Why it's wrong here
IAM conditions govern identity and API authorisation, not packet-level reachability between VM instances; they cannot express which tier may open a connection to which port. It is tempting because service accounts do provide per-tier identity and least-privilege API access, which is the correct control for service-to-service authentication rather than network segmentation.
Go deeper
Related to this question
Learn chapter
Google Kubernetes Engine (GKE)
Key term
CAN
A CAN (Controller Area Network) is a robust vehicle bus standard designed to allow microcontrollers and devices to communicate with each other without a host computer.
Key term
Compute Engine
Compute Engine is Google Cloud's Infrastructure-as-a-Service (IaaS) offering that lets you create and run virtual machines on Google's infrastructure.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.