Courseiva

Google PCA Practice Question: Managing and Provisioning a Solution Infrastructure

An engineer needs to share a VPC network across multiple projects in an organization while maintaining centralized network administration. Which approach should they use?

⚠ Common exam trap

PCA often tests the distinction between Shared VPC (centralized admin, host/service projects) and VPC peering (decentralized, non-transitive) — candidates may pick peering thinking it achieves the same centralized control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Shared VPC

Shared VPC in Google Cloud lets an organization designate a host project whose VPC network is shared with multiple service projects. This centralizes network administration (subnets, firewall rules, routes managed in the host project) while allowing teams in service projects to deploy resources into the shared network. It is the canonical answer for cross-project network sharing with centralized control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Shared VPC

    Why this is correct

    Shared VPC lets a host project's network be shared into service projects, so subnets, firewall rules and routes stay centrally administered by the host project's admins while each service project's resources attach to it. This directly satisfies the requirement to share one VPC across projects with centralised network administration.

  • ✗

    VPC peering between all projects

    Why it's wrong here

    VPC peering connects separate VPC networks, each retaining its own administration, so it does not provide centralised control or shared subnets. It is tempting because peering links projects, but the stem requires one VPC shared from a host project to service projects.

  • ✗

    Private Google Access

    Why it's wrong here

    Private Google Access only lets instances without external IPs reach Google APIs and services; it does not share subnets or centralise network administration across projects. It is tempting because it addresses cross-project connectivity concerns, but Shared VPC is the mechanism for that requirement.

  • ✗

    Cloud VPN between projects

    Why it's wrong here

    Cloud VPN connects networks over IPsec but does not share a VPC's subnets or IAM across projects, so centralised administration is not achieved. It is tempting because VPNs link projects, yet the correct mechanism is a Shared VPC host project with service projects attached.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.