For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeGCP Professional Cloud ArchitectGCP Professional Cloud Architect Practice Exam 1Question 23
    Hard1 markMultiple Choice
    Subtask 1.3: Network, Storage, ComputeNetworkingShared VPCEnterprise Architecture

    GCP PCA · Question 23 · Network, Storage, Compute

    An enterprise has a central IT team and multiple independent development teams. The central IT team must control all network resources (subnets, firewalls, VPNs), while the development teams need full control over creating VMs and GKE clusters in their own projects. How should you design the GCP network architecture?

    Answer options:

    A.

    Create a separate VPC in each development team's project and connect them using VPC Peering.

    B.

    Create a Shared VPC in a Host Project managed by central IT, and attach the development teams' projects as Service Projects.

    C.

    Place all resources (network and compute) in a single project and use IAM conditions to restrict access.

    D.

    Use Cloud VPN to connect the development projects to a central IT project.

    How to approach this question

    Identify the GCP feature that separates network administration from compute administration across multiple projects.

    Full Answer

    B.Create a Shared VPC in a Host Project managed by central IT, and attach the development teams' projects as Service Projects.✓ Correct
    Create a Shared VPC in a Host Project managed by central IT, and attach the development teams' projects as Service Projects.
    Shared VPC is the exact solution for this organizational structure. It designates one project as a 'Host Project' where the VPC, subnets, and firewalls reside (managed by Network Admins). Other projects are attached as 'Service Projects'. Developers in Service Projects can create VMs that use the subnets from the Host Project, ensuring centralized network security.

    Common mistakes

    Selecting VPC Peering, which connects decentralized networks rather than centralizing network administration.
    Question 22All questionsQuestion 24

    Practice the full GCP Professional Cloud Architect Practice Exam 1

    50 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01**CASE STUDY: TechStream Gaming** **Company Overview:** TechStream Gaming is a global gaming com...HardQ02**CASE STUDY: TechStream Gaming** **Company Overview:** TechStream Gaming is a global gaming com...MediumQ03**CASE STUDY: TechStream Gaming** **Company Overview:** TechStream Gaming is a global gaming com...HardQ04**CASE STUDY: TechStream Gaming** **Company Overview:** TechStream Gaming is a global gaming com...MediumQ05**CASE STUDY: TechStream Gaming** **Company Overview:** TechStream Gaming is a global gaming com...Medium
    View all 50 questions →