A team wants to deploy a microservice on Cloud Run that needs to access a Cloud Memorystore for Redis instance in the same region. The Redis instance is in a VPC network. Which configuration is required for Cloud Run to reach the Redis instance?
Serverless VPC Access provides a connector that lets Cloud Run send traffic into the specified VPC, reaching the Redis instance's private IP. Without it, Cloud Run egress cannot route to Memorystore, which has no public endpoint.
Why this answer
Cloud Run is serverless and runs outside the customer VPC by default. To reach a Memorystore Redis instance inside a VPC, you must create a Serverless VPC Access connector and attach it to the Cloud Run service, enabling egress to the VPC. This provides private IP connectivity to Redis.
Exam trap
PCA often tests the misconception that Cloud Run can be placed directly in a VPC — candidates pick 'deploy within a VPC' instead of the correct Serverless VPC Access connector.
How to eliminate wrong answers
Option A is wrong because Cloud NAT provides outbound internet access for private instances, not connectivity into a VPC from serverless. Option C is wrong because Private Google Access allows VMs without external IPs to reach Google APIs, not Memorystore Redis. Option D is wrong because Cloud Run cannot be 'deployed within a VPC' in the traditional sense; it uses Serverless VPC Access connectors for VPC egress.