Google PCA Designing for Security and Compliance Practice Question
A company wants to give a new employee read-only access to all projects in their GCP organization. Which IAM role should they assign at the organization level to grant this access?
⚠ Common exam trap
PCA often tests the difference between basic roles (viewer, editor, owner) and their scope — candidates may pick roles/editor thinking it is needed to 'access' projects, but editor grants write access, violating the read-only requirement, while roles/viewer is the correct least-privilege choice.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
roles/viewer
The roles/viewer role grants read-only access to all resources within the organization, including all projects, making it the correct choice for a new employee who needs read-only access across all projects. Assigning it at the organization level ensures the permission is inherited by all projects, folders, and resources beneath. This follows the principle of least privilege for read-only access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
roles/owner
Why it's wrong here
roles/owner grants full control over projects, folders and billing, including permission to modify or delete resources, so it violates the read-only requirement. It is tempting because organisation-level owner genuinely provides visibility across every project, but that visibility comes bundled with write and administrative privileges.
- ✗
roles/editor
Why it's wrong here
roles/editor permits creating, modifying and deleting resources across all projects, which exceeds read-only access. It attracts administrators wanting broad organisation-wide visibility without full ownership, yet the primitive role still carries write permissions, whereas a read-only role such as roles/viewer grants only viewing rights.
- ✓
roles/viewer
Why this is correct
roles/viewer grants read-only access to all GCP resources within the organisation, including every project beneath it. Assigning it at the organisation level satisfies the stem's requirement for organisation-wide read-only visibility, since the role inherits down the resource hierarchy to all current and future projects.
- ✗
roles/orgadmin
Why it's wrong here
roles/orgadmin governs organisation-level IAM policy and administrative control, not resource read access, so it neither matches the requirement nor limits the employee to viewing. It tempts those equating organisation-wide scope with organisation administration, but the role manages policies and memberships rather than granting read-only project visibility.
Go deeper
Related to this question
Learn chapter
Google Cloud Resource Hierarchy and Organization
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.