Google PCA Practice Question: Analysing and Optimising Technical and Business Processes
A financial services firm runs a three-tier application on Google Cloud. The security team requires that all outbound traffic from the application tier to the internet be inspected by a centralised next-generation firewall appliance, and that the application tier have no public IP addresses. The network team wants to minimise changes to the existing VPC. Which design should the architect recommend?
⚠ Common exam trap
Many exam-takers confuse network address translation or private connectivity features with traffic inspection, when only an explicit route through the appliance can force egress through a firewall.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy the firewall appliance as a managed instance group in the application VPC and use a custom route with the appliance as the next hop for the default route.
Centralised inspection of internet-bound traffic requires the traffic to traverse the firewall appliance. By deploying the appliance in the same VPC and setting a custom default route whose next hop is the appliance, all egress from the application tier is forced through it. Instances remain private, and the existing VPC is preserved. Cloud NAT, VPC peering, and Private Service Connect do not insert an inspection middlebox into the egress path.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Deploy the firewall appliance as a managed instance group in the application VPC and use a custom route with the appliance as the next hop for the default route.
Why this is correct
Placing the appliance in the same VPC and overriding the default route to use the appliance as the next hop forces all egress through it for inspection. Instances keep private IPs and no public IPs, and the existing VPC is reused with only route and firewall rule changes, minimising network redesign. This is the standard hub-and-spoke or inline inspection pattern in a single VPC.
- ✗
Enable Private Google Access on the application subnet and use Private Service Connect for all external destinations.
Why it's wrong here
Private Google Access allows instances without public IPs to reach Google APIs and services, and Private Service Connect connects to published services, but neither provides general internet egress through a third-party inspection appliance. They solve private connectivity to specific services, not centralised internet traffic inspection, so they do not meet the requirement.
- ✗
Configure a Cloud NAT gateway on the application subnet and route all egress through it.
Why it's wrong here
Cloud NAT provides outbound internet access for instances without public IPs, but it performs network address translation only. It cannot redirect traffic through a third-party firewall appliance for inspection, so it does not satisfy the security requirement for centralised inspection. It also does not integrate with a next-generation firewall appliance in the path.
- ✗
Create a separate VPC for the firewall appliance and use VPC peering to connect it to the application VPC.
Why it's wrong here
VPC peering connects two VPC networks, but it does not allow traffic to be forced through a middlebox in the peered network. Peering routes are direct, and there is no mechanism to redirect egress to an appliance in another VPC for inspection. This design would bypass the firewall entirely, failing the security requirement.
Visual reference
Go deeper
Related to this question
Learn chapter
IAM Policies, Service Accounts, and Auditing
Key term
Service
A service is a software component or system that performs a specific function and is available to be used by other programs or users over a network.
Key term
VPC peering
VPC peering is a direct network connection between two virtual private clouds that allows them to communicate using private IP addresses as if they were part of the same network.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.