certslothcertsloth
PCNE/Topic 01

Google Cloud / Professional

VPC scope, addresses and private services

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Global network, regional subnet, deliberate boundaries.

Must remember

  • A Google VPC is global; subnets are regional. Plan non-overlapping ranges for VMs, GKE Pods/Services, managed services and hybrid networks before deployment; reserve growth and check quotas.
  • Shared VPC centralizes network administration in a host project while service projects consume permitted subnets. Network administration and subnet-use permissions are different responsibilities.
  • VPC Network Peering connects compatible networks but is not automatically transitive. Network Connectivity Center (NCC) supports managed hub/spoke connectivity; Private Service Connect (PSC) exposes supported services through consumer endpoints rather than merging entire networks.
  • Private Google Access enables eligible internal-only workloads to reach Google APIs. Private services access uses allocated ranges and service networking; PSC is a different connection model. VPC Service Controls restrict supported service data movement, not ordinary packet routing.
  • Premium versus Standard Network Service Tiers affect traffic paths and supported load-balancer designs. Select regional/global behavior explicitly; public IP ownership does not remove egress charges.
  • Plan IPv6, MTU, BYOIP or privately used public space only with supported combinations. Subnet expansion can be possible, but overlapping ranges and unsupported shrink operations complicate recovery.

Choose under exam pressure

Requirement Choice and reason
Central network team, separate application projects Shared VPC with scoped subnet-use permissions.
Expose one producer service privately Evaluate PSC instead of granting broad network connectivity.

Traps

  • VPC peering does not create a general transit network.
  • Private Google Access is not identical to private services access.

Active recall

1. What is the scope of a subnet?

Regional, within a global VPC.

2. Why reserve GKE address space early?

Pod and Service growth can exhaust secondary ranges even when VM addresses remain.

3. What does VPC Service Controls protect?

Supported managed-service data boundaries against exfiltration, alongside IAM.

4. Can a service project administer every host-project route?

Not simply because it can use a shared subnet; permissions remain separate.

5. Why check MTU end to end?

A smaller link or tunnel path can cause fragmentation or dropped large packets.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.