Courseiva

Google PCA Practice Question: Analysing and Optimising Technical and Business Processes

A financial services company is designing a new application on Google Cloud. The application must comply with PCI DSS and internal policies that require strict separation of duties and least privilege. The security team wants to ensure that developers cannot modify production resources, but they need to deploy code frequently. Which approach should the cloud architect recommend to meet these requirements while supporting continuous deployment?

⚠ Common exam trap

The trap here is using a single project with IAM conditions or granting developers production roles with approval gates, which may seem sufficient but fails to enforce strict separation of duties and least privilege.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create separate Google Cloud projects for development and production. Grant developers the roles/editor role in the development project and roles/viewer in the production project. Use Cloud Build with a service account that has the necessary permissions to deploy to production.

Separate projects provide strong isolation. Developers with editor in dev can work freely, but viewer in prod prevents direct modifications. Cloud Build with a least-privilege service account automates deployments, so developers cannot directly change production. This enforces separation of duties and least privilege while enabling frequent deployments via CI/CD.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Google Cloud Deploy to manage deployments. Grant developers the roles/clouddeploy.developer role in the production project, and configure approval gates before production deployment. Developers can approve their own deployments.

    Why it's wrong here

    Granting developers a role in the production project allows potential modifications. Self-approval violates separation of duties. Approval gates are useful but must be approved by a different party. This does not prevent developers from modifying production resources directly if the role permits, and it fails PCI DSS separation requirements.

  • ✗

    Use a single Google Cloud project with IAM conditions that restrict developers to only modify resources with a specific label (e.g., env=dev). Grant developers roles/editor, and use a Cloud Build service account with roles/owner to deploy to production.

    Why it's wrong here

    IAM conditions on labels can restrict actions, but roles/editor is broad and may allow bypasses. Using a service account with roles/owner violates least privilege. A single project increases blast radius and may not satisfy strict separation. This approach is less secure and not recommended for PCI DSS compliance.

  • ✓

    Create separate Google Cloud projects for development and production. Grant developers the roles/editor role in the development project and roles/viewer in the production project. Use Cloud Build with a service account that has the necessary permissions to deploy to production.

    Why this is correct

    Separate projects enforce isolation. Developers have editor in dev (can deploy and test) but only viewer in prod (cannot modify). Cloud Build uses a dedicated service account with least privilege to deploy to production, ensuring developers cannot directly modify prod. This meets separation of duties and least privilege while enabling CI/CD through automation.

  • ✗

    Implement a CI/CD pipeline using Cloud Build and Artifact Registry. Grant developers the roles/cloudbuild.builds.editor role to trigger builds. Store production deployment credentials in Secret Manager and allow developers to access them.

    Why it's wrong here

    Allowing developers to access production deployment credentials violates least privilege and separation of duties. They could directly deploy or modify production. While Cloud Build and Artifact Registry are good practices, the credential access is a critical flaw. Production credentials should be restricted to the CI/CD service account only.

About these practice questions

Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.