Courseiva

Google PCA Design and plan a cloud solution architecture Practice Question

Network Topology
gcloud services listenabledfilter="name:container.googleapis.com"gcloud container clusters listregion=us-central1NAME TITLEcontainer.googleapis.com Kubernetes Engine APIprivateClusterConfig:enablePrivateEndpoint: trueenablePrivateNodes: truemasterIpv4CidrBlock: 172.16.0.0/28peeringName: gke-svc-xxxpublicEndpoint: false

Refer to the exhibit. A developer is trying to connect to the Kubernetes API server from their workstation using the master IP (34.67.89.12) but receives a timeout. The developer can reach other external IPs. What is the most likely reason for the timeout?

⚠ Common exam trap

Google PCA often tests the distinction between a private GKE cluster with public endpoint disabled versus a cluster that is simply in a different region or has firewall issues, leading candidates to overlook the fact that a timeout from outside the VPC indicates the endpoint is not publicly accessible.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The private cluster is configured with a private endpoint and public endpoint disabled, so the master IP is not accessible from outside the VPC.

A private GKE cluster with a private endpoint and public endpoint disabled means the Kubernetes API server is only reachable from within the cluster's VPC network. The developer's workstation is outside the VPC, so attempts to reach the master IP (34.67.89.12) will time out, even though other external IPs are reachable. This is a common configuration for security-sensitive workloads that require the API server to be isolated from the public internet.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The cluster is in a different region than the developer's VPC.

    Why it's wrong here

    Region placement does not cause a timeout when the master IP is public and other external IPs are reachable; authorised networks and firewall rules govern access. It is tempting because latency or cross-region routing can affect connectivity, but the master endpoint is reachable globally unless access is restricted.

  • ✗

    The developer's workstation does not have the required firewall rule to allow traffic to the master IP.

    Why it's wrong here

    The workstation's outbound firewall would also block other external IPs, which the stem says are reachable, so it is not the cause. It is tempting because local firewall rules commonly block traffic, but the timeout stems from the cluster's master authorised networks not including the developer's IP.

  • ✓

    The private cluster is configured with a private endpoint and public endpoint disabled, so the master IP is not accessible from outside the VPC.

    Why this is correct

    A private endpoint with public endpoint disabled removes the externally routable master IP entirely, so packets to 34.67.89.12 are dropped before reaching the control plane. The developer's workstation sits outside the VPC, satisfying the stem's constraint that other external IPs remain reachable while the API server times out.

  • ✗

    The Kubernetes Engine API is not enabled in the developer's project.

    Why it's wrong here

    The Kubernetes Engine API governs cluster management operations, not connectivity to the master's IP; a disabled API would prevent cluster creation or kubectl configuration, not cause a TCP timeout. It is tempting because API enablement is a common prerequisite, but the master authorised networks setting is what blocks the connection.

About these practice questions

Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.