Courseiva

Google PCA Practice Question: Managing and Provisioning a Solution Infrastructure

An organization has multiple GCP projects managed by a central operations team. They want to define a common VPC configuration in a host project and allow service projects to use it. Which networking feature should they use?

⚠ Common exam trap

The trap is confusing VPC peering with Shared VPC — peering connects two independently managed VPCs, whereas Shared VPC centralizes ownership in a host project, which is what the question's 'host project / service project' wording demands.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Shared VPC

Shared VPC allows an organization to designate a host project that owns the VPC network and subnets, and then attach service projects so their resources (VMs, GKE clusters, etc.) can use that shared network. This centralizes network administration under the operations team while letting service teams deploy workloads in their own projects. It is the canonical GCP feature for exactly this host-project/service-project pattern.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Shared VPC

    Why this is correct

    Shared VPC lets a host project export subnets to service projects, so the central team retains control of the VPC configuration while each service project deploys its own resources into those shared subnets. This directly satisfies the requirement for one common VPC defined centrally and reused across multiple GCP projects.

  • ✗

    Private Service Connect

    Why it's wrong here

    Private Service Connect publishes and consumes services across VPCs via endpoints, not a shared host-project VPC that service projects attach to. It is tempting because it does connect projects privately, which suits exposing a specific managed service rather than centralised subnet administration.

  • ✗

    Cloud VPN

    Why it's wrong here

    Cloud VPN builds encrypted tunnels between on-premises networks or VPCs over the internet, so it cannot let service projects consume a host project's subnets. It is tempting because it links networks across projects, which fits hybrid connectivity rather than shared VPC topology.

  • ✗

    VPC peering

    Why it's wrong here

    VPC peering connects two VPC networks so their subnets route to each other, but each project keeps its own VPC rather than using the host project's. It is tempting because peering does join projects, which suits connecting distinct VPCs, not centralised subnet control.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Go deeper

Related to this question

About these practice questions

This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.