Google PCA Designing for Security and Compliance • Set 8
Google PCA Designing for Security and Compliance Practice Test 8 — 15 questions with explanations. Free, no signup.
A healthcare company runs a multi-tenant SaaS platform on Google Cloud. Each tenant has a dedicated folder inside a single organization, with projects for each environment. A recent audit found that a compromised service account in one tenant's dev project could enumerate and read Cloud Storage buckets belonging to other tenants because the service account had been granted roles/storage.admin at the organization level by mistake. The security team wants a preventive control that blocks any future IAM binding that grants a role to a principal at a scope broader than a single project, unless the principal is part of a small break-glass group. They also want the control to apply automatically to all new projects. What should the architect implement?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.