Courseiva

Google PCA Manage and provision cloud infrastructure Practice Question

A financial services company runs a three-tier web application on Compute Engine across three zones in us-central1. Their security team mandates that database traffic must never traverse the public internet, and that the database subnet must be reachable only from the application subnet. The network team has already created a custom VPC named fin-vpc with separate subnets for web, app, and db tiers. Which combination of controls should the architect implement to satisfy these requirements?

⚠ Common exam trap

The trap here is assuming that removing external IP addresses alone isolates a tier, when reachability from other subnets still depends on firewall rule scoping.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a firewall rule on fin-vpc that allows ingress to the db subnet only from the app subnet's CIDR range, and do not assign external IP addresses to the database instances.

Restricting access at the subnet level with a VPC firewall rule that permits ingress only from the application tier's CIDR, combined with withholding external IP addresses from database instances, directly implements both the least-privilege reachability requirement and the no-public-internet mandate. No additional networking products are needed because VPC firewall rules already scope traffic by source range and target, and internal-only addressing keeps the tier off the public internet.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a firewall rule on fin-vpc that allows ingress to the db subnet only from the app subnet's CIDR range, and do not assign external IP addresses to the database instances.

    Why this is correct

    Firewall rules in a VPC scope by target and source, so allowing ingress to the db subnet only from the app subnet CIDR restricts reachability to that tier, while omitting external IPs keeps the database off the public internet entirely. Together these satisfy both the isolation and no-public-internet mandates without extra products.

  • ✗

    Create a second VPC for the database tier and peer it to fin-vpc, then rely on the default firewall rules to block non-app traffic.

    Why it's wrong here

    VPC peering connects the two networks broadly, and peering does not create tier-level isolation by itself. Relying on default rules is also wrong because the implied rules only block ingress and allow egress; they do not selectively permit only the app subnet. The database subnet would still be reachable from the web subnet.

  • ✗

    Enable Private Google Access on the db subnet and remove external IPs from the database instances so all traffic stays internal to Google's network.

    Why it's wrong here

    Private Google Access only lets instances without external IPs reach Google APIs and services using internal addresses; it does not restrict which subnet can reach the database. Removing external IPs helps with public exposure but does nothing to limit reachability to the app tier specifically.

  • ✗

    Assign internal IP addresses to the databases and place them behind an external TCP proxy load balancer so only the app tier can resolve the backend.

    Why it's wrong here

    An external TCP proxy load balancer is a public-facing front end; traffic from clients reaches Google's edge on a public address even when backends use internal IPs. This does not guarantee database traffic never touches the public internet path, and it does not restrict reachability to the app subnet as required.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.