Google PCA Designing for Security and Compliance Practice Question
A company wants to control which resources can be accessed by a service account in a specific project. Which IAM policy binding approach should be used?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant the service account a role at the project or resource level
IAM roles are bound to members (including service accounts) at the resource, project, folder, or organization level. The correct approach is to grant the service account an IAM role at the project or resource level.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use VPC Service Controls to restrict the service account
Why it's wrong here
VPC Service Controls control data exfiltration, not IAM permissions.
- ✓
Grant the service account a role at the project or resource level
Why this is correct
IAM roles at the project or resource level restrict access to that scope.
- ✗
Add the service account to a Cloud Identity group and grant the group a role
Why it's wrong here
While possible, this is not the most direct approach and still requires role binding at the appropriate scope.
- ✗
Grant the service account a role at the organization level
Why it's wrong here
This would grant access to all resources in the organization, not just the specific project.
Go deeper
Related to this question
Learn chapter
Google Cloud Resource Hierarchy and Organization
Key term
IAM policy
An IAM policy is a set of rules that determines who can access specific cloud resources and what actions they are allowed to perform.
Key term
CAN
A CAN (Controller Area Network) is a robust vehicle bus standard designed to allow microcontrollers and devices to communicate with each other without a host computer.
About these practice questions
Courseiva writes every PCA question from scratch — 955 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.