Courseiva

Google PCA Manage and provision cloud infrastructure Practice Question

An organization has a VPC with two subnets: subnet-a (10.0.1.0/24) and subnet-b (10.0.2.0/24). They launched a Compute Engine instance in subnet-a with an internal IP 10.0.1.2 and a public IP. They want the instance to only allow HTTPS traffic from the internet. Which firewall rule should they create?

⚠ Common exam trap

It's easy for candidates to confuse ingress vs. egress rules or mistakenly restrict the source to the VPC range (10.0.0.0/16) thinking it includes the internet, when in fact it only allows traffic from within the VPC.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ingress rule: allow tcp:443, source 0.0.0.0/0, target tag 'https-server'

The instance needs to accept incoming HTTPS traffic (TCP port 443) from the internet. An ingress firewall rule with source 0.0.0.0/0 allows traffic from any external IP, and applying it to instances with the target tag 'https-server' ensures only tagged instances are affected. This matches the requirement to allow only HTTPS from the internet.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Ingress rule: allow tcp:0-65535, source 0.0.0.0/0, target tag 'https-server'

    Why it's wrong here

    Allowing tcp:0-65535 opens every port to the internet, not just HTTPS, violating the requirement to permit only HTTPS. It is tempting because it uses the correct ingress direction, 0.0.0.0/0 source and target tag, and would be correct where the instance must accept all TCP traffic from any internet source.

  • ✗

    Egress rule: allow tcp:443, destination 0.0.0.0/0, target tag 'https-server'

    Why it's wrong here

    This is an egress rule, governing outbound traffic from the instance, whereas the requirement concerns inbound HTTPS from the internet. It is tempting because port 443 and the https-server tag appear, but egress rules would be correct when restricting which external destinations the instance may initiate connections to.

  • ✗

    Ingress rule: allow tcp:443, source 10.0.0.0/16, target tag 'https-server'

    Why it's wrong here

    Source 10.0.0.0/16 restricts traffic to the internal VPC range, so internet clients cannot reach the instance on 443. It is tempting because port 443, ingress direction and the target tag are all correct, and it would be correct for allowing HTTPS only from within the VPC rather than from the internet.

  • ✓

    Ingress rule: allow tcp:443, source 0.0.0.0/0, target tag 'https-server'

    Why this is correct

    An ingress rule permitting tcp:443 from 0.0.0.0/0 satisfies the HTTPS-only requirement, since Google Cloud VPC firewall rules are stateful and default-deny, so all other inbound ports remain blocked. Applying the target tag 'https-server' scopes the rule to the tagged Compute Engine instance in subnet-a, leaving other instances unaffected.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.