Courseiva

Google ACE Setting Up a Cloud Solution Environment Practice Question

A Cloud Architect needs to understand the GCP resource hierarchy to set up proper access control. Which three resources are part of the GCP resource hierarchy? (Choose THREE.)

⚠ Common exam trap

ACE often tests the distinction between the resource hierarchy and other GCP constructs like Billing Accounts and Cloud Identity, causing candidates to incorrectly include them as part of the hierarchy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Folder

The GCP resource hierarchy is Organization → Folder → Project → Resources, so the three hierarchy nodes among the options are Organization (D), Folder (B), and Project (C). Organization (D) is the root node of the hierarchy and is tied to a Cloud Identity or Workspace domain, serving as the top-level container where organization-wide IAM policies and org policies are applied. Folder (B) sits between the organization and projects, allowing hierarchical grouping of projects so that IAM and org policies inherit down to everything beneath them. Project (C) is the fundamental resource container that holds actual GCP services and resources (VMs, buckets, datasets) and is the level at which APIs are enabled and billing is linked. Billing Account (A) is not part of the resource hierarchy; it is a separate billing construct that can be linked to one or more projects but does not participate in IAM policy inheritance. Cloud Identity (E) is an identity management service/domain that underpins the organization node, not a node in the resource hierarchy itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Billing Account

    Why it's wrong here

    Billing accounts are not nodes in the GCP resource hierarchy; they operate as separate external entities linked to projects for cost tracking and payment. A single billing account can be attached to many projects and sits at a level independent of Organization, Folders, and Projects. The hierarchy only governs resource containment and policy inheritance, not financial management, so billing accounts are not a hierarchical component.

  • ✓

    Folder

    Why this is correct

    Folders are correct because they serve as intermediate grouping nodes within the resource hierarchy, sitting directly below an Organization and above Projects. They allow you to group teams, products, or departments and apply IAM policies and organization policies at that group level, which are inherited by all contained projects. Folders can also nest other folders, enabling multi-level administrative boundaries that align with corporate structure.

  • ✓

    Project

    Why this is correct

    Projects are correct because they are the fundamental container in the GCP hierarchy that directly hold all resources such as Compute Engine instances, Cloud Storage buckets, and Kubernetes clusters. Every resource must belong to exactly one project, and projects act as the primary boundary for IAM permissions, Quotas, and billing usage. Projects are organized under folders or the organization root, and they are the level where most day-to-day resource access control is applied.

  • ✓

    Organization

    Why this is correct

    The Organization node is correct because it is the root of the entire GCP resource hierarchy, representing the company as a whole and providing a centralized point for policy administration. It is automatically created when you sign up for Google Workspace or Cloud Identity, and it grants Organization Administrators visibility and control over every folder, project, and resource in the account. IAM policies set at this level inherit down to all descendants, making it the highest authority for resource management.

  • ✗

    Cloud Identity

    Why it's wrong here

    Cloud Identity is incorrect because it is an identity-as-a-service (IDaaS) platform that supplies user accounts, groups, and SSO configuration, but it is not a container within the resource hierarchy. The resource hierarchy consists solely of Organization, Folders, Projects, and resources; Cloud Identity provides the principals (users/groups) that are referenced in IAM policies. Therefore, it exists alongside the hierarchy as an identity source, not as a structural node.

About these practice questions

Courseiva writes every ACE question from scratch — 775 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.