Courseiva
Migrate data solutionsmediumMultiple ChoiceObjective-mapped

PCDE Migrate data solutions Practice Question

A team is migrating an on-premises Oracle database to Cloud SQL for PostgreSQL using DMS. They have completed the schema conversion using Ora2Pg and are now setting up continuous migration. The source database is behind a firewall. Which connectivity method should they use for the source connection profile if they cannot use public IP?

⚠ Common exam trap

Candidates often mistake VPC peering (which only connects two Google Cloud VPCs) as a solution for on-premises to Google Cloud connectivity. However, VPC peering does not extend to on-premises networks. The correct approach is to use a VPN or Dedicated Interconnect, which establish private connectivity between on-premises and Google Cloud, enabling DMS to access the source database securely.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure a VPN or Dedicated Interconnect with VPC

Since the source Oracle database is behind a firewall and cannot use a public IP, a VPN or Dedicated Interconnect with VPC provides a private, encrypted connection between the on-premises network and Google Cloud. This allows Database Migration Service (DMS) to reach the source database securely without exposing it to the public internet. DMS supports connectivity via these private network paths when public IP is not an option.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Configure a VPN or Dedicated Interconnect with VPC

    Why this is correct

    This provides secure private connectivity from on-premises to GCP.

  • VPC peering

    Why it's wrong here

    VPC peering connects VPCs, but on-premises requires VPN or Interconnect.

  • Cloud SQL Auth Proxy

    Why it's wrong here

    Cloud SQL Auth Proxy provides encrypted connectivity and IAM-based authentication for client applications, but it does not establish a routable network path through a firewall to an on-premises Oracle source. The proxy requires outbound connectivity from the client to Cloud SQL, not inbound access to the source database; for a source behind a firewall, a VPN or Interconnect is needed to bridge the private network. It is tempting because it is commonly used for secure, authorised access to Cloud SQL instances from local environments, and would be correct for connecting an application client to Cloud SQL without exposing a public IP.

  • IP allowlisting

    Why it's wrong here

    Requires a public IP, which is not desired.

About these practice questions

Courseiva writes every PCDE question from scratch — 1,446 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCDE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCDE exam.