Google PCA Design and plan a cloud solution architecture Practice Question
A financial services firm is designing a new analytics platform on Google Cloud. Regulatory requirements mandate that data must never be replicated or processed outside the European Union, and the company wants to prevent accidental resource creation in non-EU regions regardless of which engineer is deploying. Which mechanism should the architect use to enforce this constraint?
⚠ Common exam trap
Watch out — candidates often confuse VPC Service Controls, which limit data exfiltration through APIs, with Organization Policy constraints, which actually restrict where resources can be created.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Organization Policy constraints that restrict resource locations to approved EU regions.
Organization Policy constraints enforce location restrictions centrally and deny non-compliant resource creation before it happens, independent of user permissions. IAM governs identity, VPC Service Controls govern API access and exfiltration, and Asset Inventory provides detection after the fact. Only the organization policy provides the preventive, organization-wide geographic guarantee the regulation demands.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Organization Policy constraints that restrict resource locations to approved EU regions.
Why this is correct
Organization Policy constraints such as gcp.resourceLocations let administrators define an allowlist of locations at the organization, folder, or project level. Any attempt to create a resource in a non-approved region is denied centrally, regardless of a user's IAM permissions. This provides the deterministic, organization-wide enforcement the regulator requires and cannot be bypassed by individual engineers.
- ✗
IAM roles that grant project creators permissions only in EU projects.
Why it's wrong here
IAM controls who can perform actions but not where resources can be created. A user with a project creator role could still deploy resources into non-EU regions inside an allowed project. This approach relies on human discipline and project structure rather than a hard technical boundary, so it cannot guarantee that data never leaves the EU.
- ✗
VPC Service Controls perimeters around each project to block data exfiltration.
Why it's wrong here
VPC Service Controls limit access to Google APIs from outside a perimeter and help prevent data exfiltration, but they do not restrict which regions a resource may be created in. A resource created inside the perimeter in a non-EU region would still be permitted. This tool addresses data movement, not the geographic location constraint.
- ✗
Cloud Asset Inventory alerts that notify security teams when non-EU resources appear.
Why it's wrong here
Cloud Asset Inventory can detect and alert on resources in disallowed regions, but detection happens after creation. The data may already have been stored or processed outside the EU before anyone reacts. The requirement is prevention, not after-the-fact notification, so a detective control is insufficient here.
Go deeper
Related to this question
Learn chapter
Resource Monitoring and Logging with Cloud Operations
Key term
VPC Service Controls
VPC Service Controls is a Google Cloud security feature that protects the data of managed services by defining perimeters that prevent data exfiltration and unauthorized access across public networks.
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.