Courseiva

Google PCA Practice Question: Managing and Provisioning a Solution Infrastructure

A healthcare company runs a three-tier application on Compute Engine. The database tier must be reachable only from the application tier, and the application tier must be reachable from the web tier. All tiers are in the same VPC in project prod-apps. The security team requires that rules be evaluated by source identity rather than IP ranges, and that no instance can reach the database unless explicitly allowed. Which configuration should the architect use?

⚠ Common exam trap

The trap here is treating network tags and service accounts as interchangeable firewall selectors, when only service accounts provide identity-based authorization for the source.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assign each tier a unique service account and create ingress firewall rules that specify those service accounts as sources, along with the appropriate target service accounts.

VPC firewall rules support service accounts as source and target selectors, so attaching a distinct service account to each tier and referencing those accounts in ingress rules authorizes traffic by workload identity. This enforces that only the application tier can reach the database and only the web tier can reach the application tier, without relying on IP ranges or tags.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use VPC firewall rules with target tags and source tags, assigning matching tags to instances in each tier.

    Why it's wrong here

    Tag-based rules authorize by tag, not by service account identity, so they do not satisfy the requirement to evaluate source identity. Tags are also mutable by anyone with instance edit permissions, making them weaker than service-account-based authorization for a regulated workload.

  • ✗

    Deploy all tiers into a single managed instance group and use instance group membership as the source selector in firewall rules.

    Why it's wrong here

    Firewall rules cannot select sources by managed instance group membership; they support IP ranges, tags, and service accounts. Collapsing tiers into one group also destroys the tier separation the architecture needs, so this neither meets the identity requirement nor preserves the three-tier design.

  • ✗

    Create ingress firewall rules using source IP ranges for each tier, and apply them with network tags on the instances.

    Why it's wrong here

    Source IP range rules evaluate packets by address, not by workload identity, so they fail the requirement to authorize by source identity. They also become brittle as instance IPs change, and tags alone do not express identity-based authorization, which the security team explicitly requires.

  • ✓

    Assign each tier a unique service account and create ingress firewall rules that specify those service accounts as sources, along with the appropriate target service accounts.

    Why this is correct

    Firewall rules on VPC networks can use service accounts as both source and target, which authorizes traffic based on the identity attached to the instance rather than its IP. Unique service accounts per tier plus service-account-based rules enforce least privilege and satisfy the identity-based evaluation requirement without depending on address ranges.

Go deeper

Related to this question

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.