Google PCA Practice Question: Analyze and optimize technical and business processes
Exhibit
Refer to the exhibit.
```
resource "type" "name" {
project = "my-project"
name = "example-instance"
machine_type = "e2-medium"
zone = "us-central1-a"
boot_disk {
initialize_params {
image = "debian-cloud/debian-11"
size = 10
type = "pd-standard"
}
}
network_interface {
network = "default"
access_config {
// Ephemeral public IP
}
}
}
```Refer to the exhibit. A DevOps engineer created this Terraform configuration to deploy a Compute Engine instance. After applying, they notice the instance is not accessible from the internet. What is the most likely cause?
⚠ Common exam trap
Google Cloud often tests the misconception that assigning a public IP automatically makes an instance internet-accessible, but the trap here is that without a corresponding ingress firewall rule, the instance remains isolated regardless of the public IP.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
No firewall rule allows ingress traffic to the instance.
The most likely cause is that no firewall rule allows ingress traffic to the instance. By default, GCP instances are created with a VPC network that has implied deny-all ingress rules, and unless a specific firewall rule (e.g., allowing tcp:22 for SSH or tcp:80 for HTTP) is applied to the instance's network tags or service account, all inbound traffic from the internet is blocked. The Terraform configuration shown in the exhibit likely omitted a `google_compute_firewall` resource or did not assign the necessary network tags to the instance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The machine type e2-medium does not support public IP addresses.
Why it's wrong here
Machine type determines vCPU and memory only; any Compute Engine machine type can receive an external IP. The instance likely lacks an access config or firewall rule. Machine type selection matters for workload sizing, not network reachability.
- ✗
The instance is not attached to a VPC network.
Why it's wrong here
Every Compute Engine instance is always attached to a VPC network; attachment is mandatory, so this cannot be the cause. External reachability instead depends on an external IP address, firewall rules permitting ingress, and routing. The option tempts because VPC selection matters for subnet and route configuration, but its absence is impossible in practice.
- ✓
No firewall rule allows ingress traffic to the instance.
Why this is correct
Compute Engine instances have no implicit internet ingress; traffic is blocked unless a VPC firewall rule explicitly permits it. Since the configuration defines only the instance, the absence of an ingress rule allowing the required ports is what prevents external access, regardless of external IP assignment.
- ✗
The boot disk size is too small to run the operating system.
Why it's wrong here
A small boot disk prevents the instance from booting at all, producing a startup failure rather than a running instance unreachable from the internet. Disk sizing is the correct consideration when the chosen image or workload exceeds the default 10 GB.
Go deeper
Related to this question
Learn chapter
Virtual Machine Instances in Compute Engine
Key term
VPC network
A Virtual Private Cloud (VPC) network is a logically isolated section of a public cloud provider's infrastructure where you can launch cloud resources in a virtual network that you define and control.
Key term
Compute Engine
Compute Engine is Google Cloud's Infrastructure-as-a-Service (IaaS) offering that lets you create and run virtual machines on Google's infrastructure.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.