Courseiva

Google PCA Practice Question: Analysing and Optimising Technical and Business Processes

A financial services firm runs a three-tier application on Google Cloud. The security team requires that all outbound traffic from the application tier to the internet be inspected by a centralised next-generation firewall appliance, and that the application tier have no public IP addresses. The network team wants to minimise changes to the existing VPC. Which design should the architect recommend?

⚠ Common exam trap

Many exam-takers confuse network address translation or private connectivity features with traffic inspection, when only an explicit route through the appliance can force egress through a firewall.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy the firewall appliance as a managed instance group in the application VPC and use a custom route with the appliance as the next hop for the default route.

Centralised inspection of internet-bound traffic requires the traffic to traverse the firewall appliance. By deploying the appliance in the same VPC and setting a custom default route whose next hop is the appliance, all egress from the application tier is forced through it. Instances remain private, and the existing VPC is preserved. Cloud NAT, VPC peering, and Private Service Connect do not insert an inspection middlebox into the egress path.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Deploy the firewall appliance as a managed instance group in the application VPC and use a custom route with the appliance as the next hop for the default route.

    Why this is correct

    Placing the appliance in the same VPC and overriding the default route to use the appliance as the next hop forces all egress through it for inspection. Instances keep private IPs and no public IPs, and the existing VPC is reused with only route and firewall rule changes, minimising network redesign. This is the standard hub-and-spoke or inline inspection pattern in a single VPC.

  • ✗

    Enable Private Google Access on the application subnet and use Private Service Connect for all external destinations.

    Why it's wrong here

    Private Google Access allows instances without public IPs to reach Google APIs and services, and Private Service Connect connects to published services, but neither provides general internet egress through a third-party inspection appliance. They solve private connectivity to specific services, not centralised internet traffic inspection, so they do not meet the requirement.

  • ✗

    Configure a Cloud NAT gateway on the application subnet and route all egress through it.

    Why it's wrong here

    Cloud NAT provides outbound internet access for instances without public IPs, but it performs network address translation only. It cannot redirect traffic through a third-party firewall appliance for inspection, so it does not satisfy the security requirement for centralised inspection. It also does not integrate with a next-generation firewall appliance in the path.

  • ✗

    Create a separate VPC for the firewall appliance and use VPC peering to connect it to the application VPC.

    Why it's wrong here

    VPC peering connects two VPC networks, but it does not allow traffic to be forced through a middlebox in the peered network. Peering routes are direct, and there is no mechanism to redirect egress to an appliance in another VPC for inspection. This design would bypass the firewall entirely, failing the security requirement.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.