Courseiva

Google PCA Manage and provision cloud infrastructure Practice Question

Which TWO are required to allow on-premises hosts to access Google APIs using internal IP addresses (Private Google Access)? (Choose 2)

⚠ Common exam trap

Google Cloud often tests the misconception that a Cloud Router or DNS zone is required for Private Google Access, but the core requirement is simply the private network connectivity (Cloud Interconnect or Cloud VPN) and the subnet-level feature enablement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A Cloud Interconnect or Cloud VPN connection between on-premises and VPC

Option A is correct because Private Google Access for on-premises hosts requires a hybrid connectivity path — either Cloud Interconnect or Cloud VPN — to carry traffic from the on-premises network into the VPC, where it can then reach Google APIs via internal IP addresses. Option D is correct because Private Google Access must be enabled on the specific subnet that the on-premises traffic will use; this setting allows resources in that subnet to reach Google APIs using internal IP addresses rather than external ones. Option B is incorrect because Cloud Router is a Google Cloud resource used for dynamic routing (e.g., BGP) within the VPC, not something configured in the on-premises network. Option C is incorrect because VPC Service Controls is a security perimeter feature for mitigating data exfiltration, not a requirement for Private Google Access. Option E is incorrect because a private DNS zone for googleapis.com is not required; Google provides the necessary DNS resolution for private.googleapis.com and restricted.googleapis.com automatically when Private Google Access is configured.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A Cloud Interconnect or Cloud VPN connection between on-premises and VPC

    Why this is correct

    On-premises hosts need a private path into the VPC. Cloud Interconnect or Cloud VPN provides that hybrid connectivity, carrying traffic to the subnet where Private Google Access is enabled, so Google APIs are reachable using internal addresses.

  • ✗

    A Cloud Router instance configured in the on-premises network

    Why it's wrong here

    Private Google Access is configured on the subnet and routes traffic to restricted.googleapis.com or private.googleapis.com through a Cloud Router in the VPC, not on-premises; a Cloud Router in the on-premises network cannot advertise Google API prefixes into the VPC. Cloud Router is used on-premises only for Cloud Interconnect or HA VPN BGP peering with Google's edge.

  • ✗

    VPC Service Controls enabled

    Why it's wrong here

    VPC Service Controls create a service perimeter restricting data exfiltration between projects and APIs; they do not enable on-premises hosts to reach Google APIs via internal addresses. It would be correct when isolating sensitive resources from unauthorised projects, not for establishing Private Google Access connectivity.

  • ✓

    Private Google Access enabled on the subnet that the on-premises traffic will use

    Why this is correct

    Private Google Access is a subnet-level setting. Enabling it on the subnet carrying the on-premises traffic allows instances and forwarded traffic in that subnet to reach Google APIs via internal addresses, satisfying the internal-IP requirement.

  • ✗

    A private DNS zone for googleapis.com

    Why it's wrong here

    Private Google Access relies on the default private.googleapis.com routing and DNS resolution, not a customer-created private zone for googleapis.com. A private DNS zone would be the right choice when overriding public name resolution for custom internal domains, which is unrelated to reaching Google APIs from on-premises hosts.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Go deeper

Related to this question

About these practice questions

This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.