Courseiva

Google PCA Manage implementation of cloud architecture Practice Question

Your team is deploying a new three-tier application to Google Cloud. The security team requires that the application's Compute Engine instances never receive public IP addresses, yet the instances must still download OS patches from the public internet and reach a third-party REST API over HTTPS. You need to implement this with the least operational overhead. What should you do?

⚠ Common exam trap

The trap here is assuming that firewall rules can substitute for removing a public IP address, when the requirement is about address assignment rather than traffic filtering.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure Cloud NAT on a Cloud Router in the region, and create a route so instances without external IP addresses can reach the internet.

Cloud NAT provides managed, regional outbound internet access for instances that have no external IP address. It satisfies both the security constraint and the functional need for patch downloads and third-party API calls, without introducing proxy servers, ephemeral public addresses, or on-premises dependencies. This is the lowest-overhead native option.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure Cloud NAT on a Cloud Router in the region, and create a route so instances without external IP addresses can reach the internet.

    Why this is correct

    Cloud NAT lets instances with only internal IP addresses initiate outbound connections to the internet without exposing them to inbound traffic. Attaching it to a Cloud Router in the same region and VPC supports patch downloads and third-party API calls while satisfying the no-public-IP requirement, with no per-instance agents or proxies to maintain.

  • ✗

    Create a VPN tunnel from the VPC to an on-premises network and route all internet-bound traffic through that network.

    Why it's wrong here

    Hairpinning internet traffic through on-premises systems requires an existing VPN or Interconnect, on-premises egress infrastructure, and careful routing configuration. It adds latency and operational burden and depends on external network capacity. Cloud NAT is a native, managed way to give internal-only instances outbound internet access without involving on-premises systems.

  • ✗

    Assign each instance an ephemeral external IP address and use firewall rules to block all inbound traffic on every port.

    Why it's wrong here

    Ephemeral external IPs make instances publicly addressable at the network layer, which violates the requirement that instances never receive public IP addresses. Firewall rules only filter traffic after it reaches the instance; they do not remove the public address, so the security team's explicit constraint is breached even though inbound connections might be blocked.

  • ✗

    Deploy a third-party forward proxy on a Compute Engine instance with an external IP address and point all instances at it.

    Why it's wrong here

    A forward proxy can relay outbound traffic, but it requires you to run, patch, scale, and monitor proxy instances yourself, adding significant operational overhead. It also introduces a single egress path that becomes an availability bottleneck. Cloud NAT provides the same outbound capability as a managed service, which better matches the least-overhead requirement.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.