For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeGCP Professional Cloud ArchitectGCP Professional Cloud Architect Practice Exam 3Question 42
    Hard1 markMultiple Choice
    Domain 3: Designing for Security and ComplianceDomain 3VPC Service ControlsPrivate Google AccessSecurity

    GCP PCA · Question 42 · Domain 3: Designing for Security and Compliance

    You are designing a secure data perimeter for a highly regulated project. You have implemented VPC Service Controls (VPC SC). You also have VMs in a private subnet (no external IPs) that need to access Cloud Storage buckets within the perimeter. Which TWO configurations are required to make this work? (Select TWO)

    Answer options:

    A.

    Assign a public IP address to the VMs.

    B.

    Enable Private Google Access on the subnet where the VMs reside.

    C.

    Configure Cloud NAT for the subnet.

    D.

    Create an Ingress rule in VPC SC to allow traffic from the internet.

    E.

    Ensure the VPC network containing the VMs is added to the VPC Service Controls perimeter.

    How to approach this question

    Understand how private VMs reach Google APIs (Private Google Access) and how VPC SC perimeters work (the VPC must be inside the perimeter).

    Full Answer

    B,E
    To securely access Google APIs from private VMs, you must enable Private Google Access on the subnet. This routes traffic to Google APIs internally. When VPC Service Controls is enabled, it blocks access to services like Cloud Storage. To allow the private VMs to access the storage, the VPC network hosting the VMs must be explicitly added to the VPC SC perimeter. This creates a trusted boundary containing both the VMs and the Storage buckets.

    Common mistakes

    Thinking Cloud NAT is required (C). Cloud NAT is for reaching third-party internet sites. Google APIs are reached internally via Private Google Access.
    Question 41All questionsQuestion 43

    Practice the full GCP Professional Cloud Architect Practice Exam 3

    50 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01**CASE STUDY: TechStream Gaming** **Company Overview:** TechStream Gaming is a global gaming com...MediumQ02**CASE STUDY: TechStream Gaming** **Company Overview:** TechStream Gaming is a global gaming com...HardQ03**CASE STUDY: TechStream Gaming** **Company Overview:** TechStream Gaming is a global gaming com...MediumQ04**CASE STUDY: TechStream Gaming** **Company Overview:** TechStream Gaming is a global gaming com...EasyQ05**CASE STUDY: TechStream Gaming** **Company Overview:** TechStream Gaming is a global gaming com...Medium
    View all 50 questions →