Courseiva

Google PCA Manage and provision cloud infrastructure Practice Question

An administrator is configuring firewall rules in a VPC. Two rules apply to the same traffic: rule 1 allows ingress from 0.0.0.0/0 on TCP 80, rule 2 denies ingress from 10.0.0.0/8 on TCP 80. Rule 1 has priority 1000, rule 2 has priority 500. What is the effective behavior for traffic from 10.0.0.1?

⚠ Common exam trap

Google Cloud PCA often tests the misconception that allow rules override deny rules or that rule creation order matters, but the trap here is that candidates confuse priority numbers (lower = higher priority) and assume a higher number means higher priority.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Traffic is denied because rule 2 has higher priority.

In Google Cloud VPC firewall rules, rules are evaluated in priority order, with lower numbers having higher priority. Rule 2 (priority 500) is evaluated before rule 1 (priority 1000), and since rule 2 explicitly denies ingress from 10.0.0.0/8 on TCP 80, traffic from 10.0.0.1 is denied. Google Cloud firewall rules are stateful, and the first matching rule determines the outcome; there is no implicit override between allow and deny.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The result is unpredictable without knowing the rule creation order.

    Why it's wrong here

    Rule evaluation is deterministic: the firewall compares numeric priority values, and the lower number wins regardless of creation order. Creation order is tempting because many ACL systems are order-dependent, but this VPC firewall uses explicit priority numbers, so the outcome is fully predictable.

  • ✗

    Traffic is allowed because allow rules override deny rules.

    Why it's wrong here

    VPC firewall rules are evaluated by priority, not by an allow-overrides-deny hierarchy; the deny at priority 500 is reached first and terminates evaluation. Allow-overrides-deny is tempting from IAM or security-group habits, but here the lower-numbered deny rule takes precedence.

  • ✓

    Traffic is denied because rule 2 has higher priority.

    Why this is correct

    VPC firewall rules are evaluated by priority, where the lowest numeric value wins; rule 2's priority 500 beats rule 1's 1000. Because 10.0.0.1 falls inside 10.0.0.0/8, the deny rule matches first and takes effect, so the connection is blocked despite the broader allow.

  • ✗

    Traffic is allowed because rule 1 has a lower priority number.

    Why it's wrong here

    Lower priority numbers win, so rule 2's priority 500 deny is evaluated before rule 1's priority 1000 allow, blocking the traffic. The option inverts the mechanism; it is tempting because lower numbers intuitively suggest weaker precedence, but here they mean earlier evaluation.

About these practice questions

Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.