Courseiva

Google PCA Design and plan a cloud solution architecture Practice Question

An analytics team runs a batch pipeline that reads several terabytes of data from a Cloud Storage bucket in us-central1 every night. To reduce egress and improve throughput, they decide to run the pipeline on Compute Engine VMs in the same region and want the traffic to stay on Google's internal network without traversing the public internet. They also want the VMs to reach Google APIs such as Cloud Storage and BigQuery. Which configuration should the architect recommend?

⚠ Common exam trap

The trap here is conflating internet access for VMs with private access to Google APIs, when Private Google Access specifically enables the latter without external IPs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the VMs without external IPs and enable Private Google Access on the subnet

Private Google Access on the subnet is the supported mechanism that lets VMs with internal-only addresses reach Google APIs and services over Google's internal network. Because the VMs and the Cloud Storage bucket are in the same region, this configuration also keeps traffic local, reduces public internet exposure, and avoids the cost and complexity of NAT gateways or external IP addresses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure the VMs without external IPs and enable Private Google Access on the subnet

    Why this is correct

    Private Google Access allows VMs with only internal IP addresses to reach Google APIs and services through internal routing, keeping traffic off the public internet. This satisfies both the private connectivity goal and the requirement to access Cloud Storage and BigQuery from the same-region VMs without assigning external addresses.

  • ✗

    Assign external IP addresses to the VMs and rely on default internet routing to reach Google APIs

    Why it's wrong here

    External IP addresses cause traffic to Google APIs to potentially leave Google's network and traverse the public internet, which contradicts the goal of staying on the internal network. It also exposes the VMs unnecessarily and does not reduce egress costs or improve the private path to Cloud Storage and BigQuery in the way the team requires.

  • ✗

    Deploy a NAT gateway on a separate VM and route all API traffic through it

    Why it's wrong here

    A self-managed NAT gateway would let internal-only VMs reach the internet, but it adds a single point of failure and management overhead, and it does not provide the optimized private path to Google APIs that Private Google Access offers. It also still sends API traffic through a translation hop rather than keeping it on Google's internal backbone.

  • ✗

    Create a VPC peering connection between the project and the googleapis.com service project

    Why it's wrong here

    VPC peering cannot be established with Google's public API service infrastructure in this manner, so this approach is not a supported way to reach Cloud Storage or BigQuery. Private connectivity to Google APIs is provided through Private Google Access or Private Service Connect, not through user-created peering to a service project.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.