Courseiva

Google PCA Practice Question: Managing Implementation and Ensuring Solution and Operations Reliability

A financial services company runs a payment API on Compute Engine behind an internal passthrough Network Load Balancer. The compliance team requires that all administrative actions on the project be attributable to a named human, that production changes be reviewed before taking effect, and that no single engineer can delete the production database. Which combination of Google Cloud controls should the cloud architect implement?

⚠ Common exam trap

The trap here is treating detective controls such as audit log exports or deletion alerts as sufficient, when the compliance requirements demand preventive controls that stop unauthorized or unreviewed actions before they occur.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assign least-privilege predefined roles to engineers, require all production changes to go through a CI/CD pipeline that uses a dedicated service account in a separate project, and protect the production database with a resource-level deny policy and separation of duties.

The compliance demands map to preventive controls: least privilege to limit permissions, a reviewed CI/CD pipeline with a dedicated service account in a separate project to enforce change review and attribution, and a resource-level deny policy plus separation of duties to stop any one engineer from deleting the production database. Detective measures like audit logging and alerting are useful but insufficient on their own. The combination of IAM restrictions, automation, and deny policies satisfies all three requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Require all engineers to use hardware security keys for two-factor authentication, enable Identity-Aware Proxy for SSH access to instances, and create an alerting policy that notifies the security team when the database is deleted.

    Why it's wrong here

    Strong authentication and Identity-Aware Proxy improve access security for interactive sessions, but they do not constrain what an authenticated engineer is authorized to do in IAM. An alert after database deletion is purely detective and arrives too late to prevent the destructive action. None of these controls enforce review of production changes or prevent any single engineer from having delete permissions.

  • ✓

    Assign least-privilege predefined roles to engineers, require all production changes to go through a CI/CD pipeline that uses a dedicated service account in a separate project, and protect the production database with a resource-level deny policy and separation of duties.

    Why this is correct

    Least-privilege roles limit what each engineer can do, and a pipeline with a dedicated service account in a separate project ensures changes are reviewed and executed by automation rather than directly by humans. A deny policy on the database prevents even privileged users from deleting it, and separation of duties keeps one person from both proposing and approving. This gives attribution, review, and protection.

  • ✗

    Grant the Project Owner role to all senior engineers, enable Cloud Audit Logs for Admin Activity, and require them to use a shared break-glass account for emergency changes.

    Why it's wrong here

    Project Owner is far too broad and allows deletion of any resource, including the production database, so it violates separation of duties. A shared break-glass account destroys individual attribution because actions cannot be traced to a named human. Admin Activity logs alone record what happened but do not enforce review or prevent destructive actions, so this combination fails every stated compliance requirement.

  • ✗

    Enable VPC Service Controls around the production project, grant engineers the Editor role, and configure Cloud Logging sinks to export audit logs to a separate project for long-term retention.

    Why it's wrong here

    VPC Service Controls helps prevent data exfiltration but does not restrict administrative deletion of a database or enforce change review. The Editor role is a basic role that includes broad permissions, including many delete operations, so it violates least privilege and separation of duties. Exporting logs improves retention and investigation but is detective, not preventive, so it cannot stop a single engineer from deleting the production database.

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.