Google PCA Practice Question: Managing and Provisioning a Solution Infrastructure
An engineer needs to share a VPC network across multiple projects in an organization while maintaining centralized network administration. Which approach should they use?
⚠ Common exam trap
PCA often tests the distinction between Shared VPC (centralized admin, host/service projects) and VPC peering (decentralized, non-transitive) — candidates may pick peering thinking it achieves the same centralized control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Shared VPC
Shared VPC in Google Cloud lets an organization designate a host project whose VPC network is shared with multiple service projects. This centralizes network administration (subnets, firewall rules, routes managed in the host project) while allowing teams in service projects to deploy resources into the shared network. It is the canonical answer for cross-project network sharing with centralized control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Shared VPC
Why this is correct
Shared VPC lets a host project's network be shared into service projects, so subnets, firewall rules and routes stay centrally administered by the host project's admins while each service project's resources attach to it. This directly satisfies the requirement to share one VPC across projects with centralised network administration.
- ✗
VPC peering between all projects
Why it's wrong here
VPC peering connects separate VPC networks, each retaining its own administration, so it does not provide centralised control or shared subnets. It is tempting because peering links projects, but the stem requires one VPC shared from a host project to service projects.
- ✗
Private Google Access
Why it's wrong here
Private Google Access only lets instances without external IPs reach Google APIs and services; it does not share subnets or centralise network administration across projects. It is tempting because it addresses cross-project connectivity concerns, but Shared VPC is the mechanism for that requirement.
- ✗
Cloud VPN between projects
Why it's wrong here
Cloud VPN connects networks over IPsec but does not share a VPC's subnets or IAM across projects, so centralised administration is not achieved. It is tempting because VPNs link projects, yet the correct mechanism is a Shared VPC host project with service projects attached.
Visual reference
Go deeper
Related to this question
Learn chapter
VPC Peering and Shared VPC
Key term
VPC network
A Virtual Private Cloud (VPC) network is a logically isolated section of a public cloud provider's infrastructure where you can launch cloud resources in a virtual network that you define and control.
Key term
Service
A service is a software component or system that performs a specific function and is available to be used by other programs or users over a network.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.