Courseiva

Google PCA Ensure solution and operations reliability Practice Question

Network Topology
gcloud logging read "resource.type=gce_instancelimit 5format=json"severity": "ERROR","textPayload": "Connection refused to 10.0.0.1:5432","resource": {"labels": {"instance_id": "1234567890"},"timestamp": "2024-05-01T10:00:00Z""timestamp": "2024-05-01T10:05:00Z"

Refer to the exhibit. An application running on a GCE instance (ID: 1234567890) is unable to connect to a database at 10.0.0.1:5432. The logs show repeated 'Connection refused' errors. What is the most likely cause?

⚠ Common exam trap

Google PCA exams often test the distinction between firewall blocks (timeout) and service unavailability (connection refused), so the trap here is that candidates confuse a missing firewall rule with a service not listening, even though the error messages are fundamentally different.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The database service is not running or is not listening on port 5432.

The 'Connection refused' error indicates that the TCP handshake was rejected by the target host, which typically means the database service is not actively listening on port 5432. This is distinct from a firewall block, which would result in a timeout or 'no route to host' error. Since the error is immediate and specific to port 5432, the most likely cause is that the PostgreSQL or other database service is not running or is bound to a different interface/port.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The firewall rule allowing traffic on port 5432 is missing or misconfigured.

    Why it's wrong here

    A missing or misconfigured firewall rule on port 5432 blocks the connection, and the correct answer here is the database service not listening on that port. Firewall rules are the right focus when traffic is silently dropped rather than actively refused.

  • ✗

    The instance is using an outdated SSL certificate.

    Why it's wrong here

    An outdated certificate would cause TLS handshake or validation failures, not the immediate TCP refusal logged here. Certificate renewal is the right fix when clients report expired or untrusted certificate errors, but a refused connection means nothing is listening on that port.

  • ✓

    The database service is not running or is not listening on port 5432.

    Why this is correct

    A refused TCP connection means the host is reachable but nothing accepts traffic on port 5432, indicating the database process is stopped or bound elsewhere. Firewall or routing problems would typically produce timeouts, not refusals.

  • ✗

    The VPC network has no route to the database subnet.

    Why it's wrong here

    A missing route produces a no-route-to-host or timeout error, not an immediate connection refusal. Route configuration is the correct focus when packets cannot reach the destination subnet at all, whereas refusal means the host was reached but the port rejected the connection.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.