PCNE Implementing VPC Instances Practice Question
An organization wants to allow on-premises hosts to connect to a Cloud SQL instance privately without traversing the public internet. They have a Cloud VPN tunnel set up. What additional step is required?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Private Service Connect on the Cloud SQL instance
Private Service Connect enables private connectivity to Google-managed services from on-premises via VPC and VPN.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a VPC peering connection
Why it's wrong here
VPC peering connects two VPCs, not on-premises.
- ✗
Add a route with next hop set to the VPN gateway
Why it's wrong here
A route alone doesn't enable private access to Cloud SQL.
- ✗
Configure Cloud NAT
Why it's wrong here
Cloud NAT provides internet access, not private connectivity.
- ✓
Enable Private Service Connect on the Cloud SQL instance
Why this is correct
Private Service Connect allows private access to managed services from on-premises via VPN.
Go deeper
Related to this question
About these practice questions
This PCNE question is part of Courseiva's 961-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNE exam.