Google PCA Design for security and compliance Practice Question
An engineering team runs workloads on Compute Engine instances in a single VPC. The security team wants the instances to reach Google APIs such as Cloud Storage and BigQuery without any traffic traversing the public internet, and without managing service account key files on disk. The architect must choose the configuration that meets both goals. Which approach should the architect recommend?
⚠ Common exam trap
The trap here is treating Private Google Access as a complete solution while forgetting that credential management is a separate requirement, or assuming a NAT gateway keeps Google API traffic off the internet.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Private Google Access on the subnet and attach a user-managed service account to the instances
Private Google Access allows instances that have no external IP address to reach Google APIs and services through internal Google routing, keeping traffic off the public internet. Attaching a user-managed service account lets the instance obtain short-lived tokens from the metadata server, so no long-lived key files are stored on disk. The other options either route traffic over the internet or retain static keys.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy a third-party NAT gateway and route all Google API traffic through it with static service account keys
Why it's wrong here
A NAT gateway would allow egress but the traffic still exits to the internet to reach public Google API endpoints, so the no-public-internet requirement is unmet. Static service account keys stored on disk also contradict the goal of eliminating key file management.
- ✗
Configure Cloud VPN to an on-premises proxy that forwards API calls to Google
Why it's wrong here
Hairpinning API calls through on-premises infrastructure adds latency, cost, and a fragile dependency, and the final hop from the proxy to Google still uses the public internet unless a dedicated interconnect path exists. It also does not address key file management on the instances.
- ✓
Enable Private Google Access on the subnet and attach a user-managed service account to the instances
Why this is correct
Private Google Access lets instances without external IPs reach Google APIs and services using internal routing, so no traffic traverses the public internet. Attaching a user-managed service account lets the instance metadata server issue short-lived credentials, eliminating downloaded key files. Together they satisfy both the network and credential requirements.
- ✗
Assign an external IP to each instance and configure firewall rules to allow egress to Google API IP ranges
Why it's wrong here
Traffic to Google APIs over an external IP leaves the VPC and transits the public internet, which violates the requirement. It also does nothing to remove service account key files, since the application still needs credentials. This approach fails both stated goals.
Go deeper
Related to this question
Learn chapter
Cloud Storage: Objects and Buckets
Key term
IP address
An IP address is a unique numerical label assigned to each device connected to a computer network that uses the Internet Protocol for communication.
Key term
Service account key
A service account key is a credential file used to authenticate and authorize a non-human user, like an application or a virtual machine, to access Google Cloud resources.
About these practice questions
Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.