Courseiva

Google PCA Designing for Security and Compliance Practice Question

A company wants to give a new employee read-only access to all projects in their GCP organization. Which IAM role should they assign at the organization level to grant this access?

⚠ Common exam trap

PCA often tests the difference between basic roles (viewer, editor, owner) and their scope — candidates may pick roles/editor thinking it is needed to 'access' projects, but editor grants write access, violating the read-only requirement, while roles/viewer is the correct least-privilege choice.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

roles/viewer

The roles/viewer role grants read-only access to all resources within the organization, including all projects, making it the correct choice for a new employee who needs read-only access across all projects. Assigning it at the organization level ensures the permission is inherited by all projects, folders, and resources beneath. This follows the principle of least privilege for read-only access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    roles/owner

    Why it's wrong here

    roles/owner grants full control over projects, folders and billing, including permission to modify or delete resources, so it violates the read-only requirement. It is tempting because organisation-level owner genuinely provides visibility across every project, but that visibility comes bundled with write and administrative privileges.

  • ✗

    roles/editor

    Why it's wrong here

    roles/editor permits creating, modifying and deleting resources across all projects, which exceeds read-only access. It attracts administrators wanting broad organisation-wide visibility without full ownership, yet the primitive role still carries write permissions, whereas a read-only role such as roles/viewer grants only viewing rights.

  • ✓

    roles/viewer

    Why this is correct

    roles/viewer grants read-only access to all GCP resources within the organisation, including every project beneath it. Assigning it at the organisation level satisfies the stem's requirement for organisation-wide read-only visibility, since the role inherits down the resource hierarchy to all current and future projects.

  • ✗

    roles/orgadmin

    Why it's wrong here

    roles/orgadmin governs organisation-level IAM policy and administrative control, not resource read access, so it neither matches the requirement nor limits the employee to viewing. It tempts those equating organisation-wide scope with organisation administration, but the role manages policies and memberships rather than granting read-only project visibility.

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.