Courseiva

Google PCA Design and plan a cloud solution architecture Practice Question

A financial services firm is designing the network for a new payment processing platform on Google Cloud. Regulatory rules require that no workload can reach the public internet, that all egress to an on-premises fraud-detection system stay off the public internet, and that Google APIs such as Cloud Storage and BigQuery remain reachable without exposing the workloads. The platform runs on Compute Engine VMs in a single VPC. Which two design elements must the architect include? (Choose two.)

⚠ Common exam trap

The trap here is reaching for Cloud NAT as the default answer for private workloads, when NAT provides internet egress and does nothing for private on-premises connectivity or Google API access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create the subnet with the --enable-private-ip-google-access option so the VMs can reach Google APIs and services without external IP addresses.

Two independent constraints must be satisfied: Google APIs stay reachable while workloads have no public addresses, and on-premises traffic stays off the internet. Private Google Access on the subnet handles the first by routing API traffic internally, and a Cloud VPN or Interconnect link with Cloud Router BGP handles the second by providing private connectivity to the fraud-detection system. Cloud NAT, external IPs, and proxy VMs all push traffic onto the public internet.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a Cloud NAT gateway with a manual IP address allocation on the VPC so the VMs can reach the fraud-detection system.

    Why it's wrong here

    Cloud NAT provides outbound internet access for internal-only VMs, which is the opposite of what is required. It also does not carry traffic to an on-premises system; that path is provided by Cloud VPN or Cloud Interconnect. Using it here would violate the rule that workloads must not reach the public internet and would not establish the private path to the fraud system.

  • ✗

    Deploy a Squid proxy on a VM with an external IP and route all VPC egress through it using a custom route with the proxy as the next hop.

    Why it's wrong here

    A proxy with an external IP reintroduces public internet exposure and creates a single, manually managed choke point that must be patched and scaled. Custom routes with a VM next hop also require enabling IP forwarding and careful firewall rules, and they still do not provide the private on-premises path. This adds operational risk without meeting either regulatory requirement.

  • ✗

    Assign ephemeral external IP addresses to the VMs and protect them with a firewall rule that allows only the fraud-detection system's source range.

    Why it's wrong here

    External IP addresses place the workloads on the public internet, directly violating the regulatory constraint, and firewall rules on the VPC do not control traffic once it leaves the Google network. Ephemeral addresses also change on stop and start, so a source-range rule would break. This design neither isolates the workloads nor creates a private path to on-premises.

  • ✓

    Create the subnet with the --enable-private-ip-google-access option so the VMs can reach Google APIs and services without external IP addresses.

    Why this is correct

    Private Google Access lets a VM with only an internal IP address reach the external IP addresses of Google APIs and services. Because the traffic stays on Google's network rather than traversing the internet, it satisfies the requirement to keep Google APIs reachable without giving the workloads public addresses. Without it, a VM lacking an external IP cannot resolve or route to those APIs.

  • ✓

    Establish a Cloud VPN tunnel or Cloud Interconnect attachment from the VPC to the on-premises network, with routes exchanged over Cloud Router using BGP.

    Why this is correct

    Reaching an on-premises fraud-detection system without using the public internet requires a private connectivity path. A Cloud VPN tunnel or a Dedicated or Partner Interconnect attachment, paired with Cloud Router running BGP, advertises on-premises prefixes into the VPC and VPC subnets back to the on-premises network, keeping that traffic on private links.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.