Google PCA Manage implementation of cloud architecture Practice Question
Your team is deploying a new three-tier application to Google Cloud. The security team requires that the application's Compute Engine instances never receive public IP addresses, yet the instances must still download OS patches from the public internet and reach a third-party REST API over HTTPS. You need to implement this with the least operational overhead. What should you do?
⚠ Common exam trap
The trap here is assuming that firewall rules can substitute for removing a public IP address, when the requirement is about address assignment rather than traffic filtering.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure Cloud NAT on a Cloud Router in the region, and create a route so instances without external IP addresses can reach the internet.
Cloud NAT provides managed, regional outbound internet access for instances that have no external IP address. It satisfies both the security constraint and the functional need for patch downloads and third-party API calls, without introducing proxy servers, ephemeral public addresses, or on-premises dependencies. This is the lowest-overhead native option.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure Cloud NAT on a Cloud Router in the region, and create a route so instances without external IP addresses can reach the internet.
Why this is correct
Cloud NAT lets instances with only internal IP addresses initiate outbound connections to the internet without exposing them to inbound traffic. Attaching it to a Cloud Router in the same region and VPC supports patch downloads and third-party API calls while satisfying the no-public-IP requirement, with no per-instance agents or proxies to maintain.
- ✗
Create a VPN tunnel from the VPC to an on-premises network and route all internet-bound traffic through that network.
Why it's wrong here
Hairpinning internet traffic through on-premises systems requires an existing VPN or Interconnect, on-premises egress infrastructure, and careful routing configuration. It adds latency and operational burden and depends on external network capacity. Cloud NAT is a native, managed way to give internal-only instances outbound internet access without involving on-premises systems.
- ✗
Assign each instance an ephemeral external IP address and use firewall rules to block all inbound traffic on every port.
Why it's wrong here
Ephemeral external IPs make instances publicly addressable at the network layer, which violates the requirement that instances never receive public IP addresses. Firewall rules only filter traffic after it reaches the instance; they do not remove the public address, so the security team's explicit constraint is breached even though inbound connections might be blocked.
- ✗
Deploy a third-party forward proxy on a Compute Engine instance with an external IP address and point all instances at it.
Why it's wrong here
A forward proxy can relay outbound traffic, but it requires you to run, patch, scale, and monitor proxy instances yourself, adding significant operational overhead. It also introduces a single egress path that becomes an availability bottleneck. Cloud NAT provides the same outbound capability as a managed service, which better matches the least-overhead requirement.
Visual reference
Go deeper
Related to this question
Learn chapter
Identity and Access Management (IAM)
Key term
HTTPS
HTTPS (Hypertext Transfer Protocol Secure) is the secure version of HTTP that encrypts data between a web browser and a web server using SSL/TLS protocols.
Key term
Cloud NAT
Cloud NAT is a managed network address translation service that allows private cloud resources to initiate outbound internet connections while keeping them unreachable from the internet.
About these practice questions
This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.