Google PCA Design and plan a cloud solution architecture Practice Question
An analytics team runs a batch pipeline that reads several terabytes of data from a Cloud Storage bucket in us-central1 every night. To reduce egress and improve throughput, they decide to run the pipeline on Compute Engine VMs in the same region and want the traffic to stay on Google's internal network without traversing the public internet. They also want the VMs to reach Google APIs such as Cloud Storage and BigQuery. Which configuration should the architect recommend?
⚠ Common exam trap
The trap here is conflating internet access for VMs with private access to Google APIs, when Private Google Access specifically enables the latter without external IPs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the VMs without external IPs and enable Private Google Access on the subnet
Private Google Access on the subnet is the supported mechanism that lets VMs with internal-only addresses reach Google APIs and services over Google's internal network. Because the VMs and the Cloud Storage bucket are in the same region, this configuration also keeps traffic local, reduces public internet exposure, and avoids the cost and complexity of NAT gateways or external IP addresses.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure the VMs without external IPs and enable Private Google Access on the subnet
Why this is correct
Private Google Access allows VMs with only internal IP addresses to reach Google APIs and services through internal routing, keeping traffic off the public internet. This satisfies both the private connectivity goal and the requirement to access Cloud Storage and BigQuery from the same-region VMs without assigning external addresses.
- ✗
Assign external IP addresses to the VMs and rely on default internet routing to reach Google APIs
Why it's wrong here
External IP addresses cause traffic to Google APIs to potentially leave Google's network and traverse the public internet, which contradicts the goal of staying on the internal network. It also exposes the VMs unnecessarily and does not reduce egress costs or improve the private path to Cloud Storage and BigQuery in the way the team requires.
- ✗
Deploy a NAT gateway on a separate VM and route all API traffic through it
Why it's wrong here
A self-managed NAT gateway would let internal-only VMs reach the internet, but it adds a single point of failure and management overhead, and it does not provide the optimized private path to Google APIs that Private Google Access offers. It also still sends API traffic through a translation hop rather than keeping it on Google's internal backbone.
- ✗
Create a VPC peering connection between the project and the googleapis.com service project
Why it's wrong here
VPC peering cannot be established with Google's public API service infrastructure in this manner, so this approach is not a supported way to reach Cloud Storage or BigQuery. Private connectivity to Google APIs is provided through Private Google Access or Private Service Connect, not through user-created peering to a service project.
Visual reference
Go deeper
Related to this question
Learn chapter
Virtual Private Cloud (VPC) Networking Basics
Key term
Data
Data is raw, unprocessed information, like numbers, words, or measurements, that can be stored, processed, and analyzed by computers.
Key term
Batch
Batch is a cloud computing service that runs large numbers of computing jobs as a group, or batch, without needing to manage individual servers.
About these practice questions
This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.