PCNE Implementing VPC Instances Practice Question
A company wants to restrict access to Google Cloud Storage so that only traffic originating from a specific VPC network is allowed. They also need to prevent data exfiltration to other VPCs. Which two services should they use? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VPC Service Controls
VPC Service Controls creates a service perimeter around the Storage API, and Private Google Access enables VMs without external IPs to access Google APIs from within the VPC.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
VPC Service Controls
Why this is correct
Creates a perimeter to restrict access.
- ✗
Cloud VPN
Why it's wrong here
Used for hybrid connectivity, not API access control.
- ✗
Cloud NAT
Why it's wrong here
Provides internet access, not restriction.
- ✗
Firewall rules
Why it's wrong here
Firewall rules cannot restrict API access at the application layer.
- ✓
Private Google Access
Why this is correct
Allows VMs without external IPs to access Google APIs from the VPC.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNE question from scratch — 961 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNE exam.