Google PCA Manage and provision cloud infrastructure Practice Question
Which TWO are required to allow on-premises hosts to access Google APIs using internal IP addresses (Private Google Access)? (Choose 2)
⚠ Common exam trap
Google Cloud often tests the misconception that a Cloud Router or DNS zone is required for Private Google Access, but the core requirement is simply the private network connectivity (Cloud Interconnect or Cloud VPN) and the subnet-level feature enablement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A Cloud Interconnect or Cloud VPN connection between on-premises and VPC
Option A is correct because Private Google Access for on-premises hosts requires a hybrid connectivity path — either Cloud Interconnect or Cloud VPN — to carry traffic from the on-premises network into the VPC, where it can then reach Google APIs via internal IP addresses. Option D is correct because Private Google Access must be enabled on the specific subnet that the on-premises traffic will use; this setting allows resources in that subnet to reach Google APIs using internal IP addresses rather than external ones. Option B is incorrect because Cloud Router is a Google Cloud resource used for dynamic routing (e.g., BGP) within the VPC, not something configured in the on-premises network. Option C is incorrect because VPC Service Controls is a security perimeter feature for mitigating data exfiltration, not a requirement for Private Google Access. Option E is incorrect because a private DNS zone for googleapis.com is not required; Google provides the necessary DNS resolution for private.googleapis.com and restricted.googleapis.com automatically when Private Google Access is configured.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A Cloud Interconnect or Cloud VPN connection between on-premises and VPC
Why this is correct
On-premises hosts need a private path into the VPC. Cloud Interconnect or Cloud VPN provides that hybrid connectivity, carrying traffic to the subnet where Private Google Access is enabled, so Google APIs are reachable using internal addresses.
- ✗
A Cloud Router instance configured in the on-premises network
Why it's wrong here
Private Google Access is configured on the subnet and routes traffic to restricted.googleapis.com or private.googleapis.com through a Cloud Router in the VPC, not on-premises; a Cloud Router in the on-premises network cannot advertise Google API prefixes into the VPC. Cloud Router is used on-premises only for Cloud Interconnect or HA VPN BGP peering with Google's edge.
- ✗
VPC Service Controls enabled
Why it's wrong here
VPC Service Controls create a service perimeter restricting data exfiltration between projects and APIs; they do not enable on-premises hosts to reach Google APIs via internal addresses. It would be correct when isolating sensitive resources from unauthorised projects, not for establishing Private Google Access connectivity.
- ✓
Private Google Access enabled on the subnet that the on-premises traffic will use
Why this is correct
Private Google Access is a subnet-level setting. Enabling it on the subnet carrying the on-premises traffic allows instances and forwarded traffic in that subnet to reach Google APIs via internal addresses, satisfying the internal-IP requirement.
- ✗
A private DNS zone for googleapis.com
Why it's wrong here
Private Google Access relies on the default private.googleapis.com routing and DNS resolution, not a customer-created private zone for googleapis.com. A private DNS zone would be the right choice when overriding public name resolution for custom internal domains, which is unrelated to reaching Google APIs from on-premises hosts.
Visual reference
Go deeper
Related to this question
Learn chapter
IAM Policies, Service Accounts, and Auditing
Key term
Cloud Interconnect
Cloud Interconnect is a service that provides a dedicated, private, high-bandwidth connection between your on-premises network and a cloud provider's network, bypassing the public internet for improved reliability, security, and performance.
Key term
Start of Authority
A Start of Authority (SOA) record is a special DNS record that stores essential administrative information about a domain, including the primary name server, the responsible administrator email, and timing parameters for caching and updates.
About these practice questions
This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.