Google PCA Design and plan a cloud solution architecture Practice Question
Exhibit
resource "google_compute_instance" "vm" {
name = "example-vm"
machine_type = "e2-medium"
zone = "us-central1-a"
boot_disk {
initialize_params {
image = "debian-cloud/debian-11"
size = 50
}
}
network_interface {
network = "default"
subnetwork = "default"
access_config {
// Ephemeral public IP
}
}
metadata = {
enable-oslogin = "TRUE"
}
}
# Output after 'terraform apply'
Apply complete! Resources: 1 added, 0 changed, 0 destroyed.
Outputs:
instance_ip = "34.123.45.67"Refer to the exhibit. An engineer deployed this Terraform configuration and can SSH to the instance using the external IP. However, they notice that the instance has a public IP address even though they intended to have no public IP. What change should be made to the configuration to ensure the instance does not get a public IP?
⚠ Common exam trap
A common trap in Google PCA is that an empty `access_config` block in Terraform for GCP still provisions a public IP, tricking candidates into thinking it means 'no public IP' when the correct fix is to remove the block entirely.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Remove the entire access_config block from the network_interface configuration.
The `access_config` block in a Terraform `google_compute_instance` resource is what assigns a public (external) IP address to the instance's network interface. By removing the entire `access_config` block, the instance will only receive a private IP address, fulfilling the requirement of no public IP. Leaving the block empty (as in option C) still creates an ephemeral external IP by default, so it does not solve the problem.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Change the metadata key enable-oslogin to FALSE.
Why it's wrong here
enable-oslogin controls SSH authentication method, not external IP allocation, so the instance retains its public address regardless of the value. Disabling OS Login is tempting when troubleshooting SSH access, and would be correct for switching to metadata-based SSH keys, not for removing public connectivity.
- ✓
Remove the entire access_config block from the network_interface configuration.
Why this is correct
In Google Compute Engine, a public IP is assigned only when the network_interface contains an access_config block. Removing it entirely leaves the interface with no external address, satisfying the requirement that the instance have no public IP.
- ✗
Set access_config = [] instead of leaving it empty.
Why it's wrong here
An empty access_config block still requests an ephemeral external IP; omitting the block entirely is what prevents one being assigned. Setting it to an empty list is tempting because it looks like declaring no access config, but it remains a present block, so the instance keeps its public address.
- ✗
Set the network to a custom VPC that does not have external internet access.
Why it's wrong here
A VPC without internet access still assigns an ephemeral external IP unless access_config is removed, because the public address comes from the instance's network interface configuration, not the VPC's routing. Choosing a private VPC is tempting for isolation, and would be correct for controlling egress, not for suppressing the external IP itself.
Go deeper
Related to this question
Learn chapter
Resource Monitoring and Logging with Cloud Operations
Key term
CAN
A CAN (Controller Area Network) is a robust vehicle bus standard designed to allow microcontrollers and devices to communicate with each other without a host computer.
Key term
IP address
An IP address is a unique numerical label assigned to each device connected to a computer network that uses the Internet Protocol for communication.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.