Google PCA Manage and provision cloud infrastructure Practice Question
Which TWO are best practices when designing a VPC network for a multi-tier application in Google Cloud?
⚠ Common exam trap
Watch out — candidates often assume a single subnet simplifies management (Option D) or that disabling flow logs is a harmless cost-saving measure (Option A), but the exam expects you to prioritize security and observability over minor cost savings or administrative convenience.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create separate subnets for each application tier.
Creating separate subnets for each application tier (e.g., web, application, database) allows you to apply granular firewall rules and routing policies per tier. This segmentation improves security by isolating traffic between tiers and aligns with Google Cloud's best practices for multi-tier architectures. It also simplifies network troubleshooting and scaling by keeping each tier's IP space distinct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable VPC Flow Logs to reduce cost.
Why it's wrong here
VPC Flow Logs are valuable for security analysis.
- ✓
Create separate subnets for each application tier.
Why this is correct
Subnets allow segmentation and granular firewall rules.
- ✓
Use firewall rules to restrict traffic between tiers to only necessary ports.
Why this is correct
Minimize attack surface by allowing only required communication.
- ✗
Use a single subnet for all tiers to simplify IP management.
Why it's wrong here
This combines all traffic and reduces security.
- ✗
Rely on the default priority of firewall rules to ensure proper ordering.
Why it's wrong here
Always set explicit priorities to avoid unintended effects.
Visual reference
Go deeper
Related to this question
Learn chapter
IAM Policies, Service Accounts, and Auditing
Key term
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules to protect trusted internal networks from untrusted external networks.
Key term
VPC network
A Virtual Private Cloud (VPC) network is a logically isolated section of a public cloud provider's infrastructure where you can launch cloud resources in a virtual network that you define and control.
About these practice questions
Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.