Courseiva

Google PCA Designing for Security and Compliance Practice Question

A company wants to centrally manage firewall rules for all projects in an organization using hierarchical firewall policies. Which three resources can be used in conjunction with hierarchical firewall policies? (Choose three.)

⚠ Common exam trap

PCA often tests the misconception that hierarchical firewall policies can be applied to VPC networks or instances directly, confusing them with VPC firewall rules.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Organization node

Hierarchical firewall policies in Google Cloud are attached at nodes of the resource hierarchy, and the three valid attachment points are the organization node (B), folders (E), and projects (C). Option B is correct because an organization-level policy applies to all resources beneath the organization and serves as the topmost layer of hierarchical firewall rules. Option E is correct because folders sit between the organization and projects, allowing policies to be scoped to a subset of projects within the hierarchy. Option C is correct because a project-level policy applies to that project's resources and is evaluated after organization and folder policies. Options A and D are not valid attachment points: a Compute Engine instance (A) is a compute resource governed by the policies, not a node where a hierarchical firewall policy is attached, and a VPC network (D) is associated with VPC firewall rules, not hierarchical firewall policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Compute Engine instance

    Why it's wrong here

    Hierarchical firewall policies attach to organisation and folder nodes, and to VPC networks; they are not bound to individual Compute Engine instances. Instance-level control comes from VPC firewall rules or network tags, so this resource cannot participate in the hierarchy.

  • ✓

    Organization node

    Why this is correct

    Hierarchical firewall policies are defined at the organisation node, which is the root of the resource hierarchy. Attaching policy there lets rules cascade to every folder and project beneath it, satisfying the requirement for centralised firewall management across all projects.

  • ✓

    Project

    Why this is correct

    A project sits at the bottom of the resource hierarchy, so hierarchical firewall policies inherited from the organisation or folder apply to it. This lets centrally defined rules govern project-level resources, satisfying the requirement for organisation-wide firewall management.

  • ✓

    Folder

    Why this is correct

    Folders sit between the organisation node and projects, so hierarchical firewall policies attached at the organisation cascade through folders to their projects. This intermediate layer satisfies the requirement for centralised, inherited firewall rules across all projects in the organisation.

Go deeper

Related to this question

About these practice questions

This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.