Google PCA Design and plan a cloud solution architecture Practice Question
A financial services firm is planning its Google Cloud resource hierarchy before migrating production workloads. The architecture team wants to enforce separation between business units, centralize network administration, and apply consistent IAM and policy controls across many projects. Which two design choices should the architect recommend? (Choose two.)
⚠ Common exam trap
The trap here is treating the organization node as something that can be created per business unit, when it actually maps to a single identity domain and is created once.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a Shared VPC host project to centralize network administration while service projects host the workloads
A folder-based hierarchy with inherited IAM and Organization Policy constraints gives centralized, consistent governance while separating business units. A Shared VPC host project centralizes network administration so service projects can consume subnets without owning network topology. Together these choices provide the separation, centralization, and consistent controls the firm requires while avoiding the risks of flat hierarchies or excessive organization-level permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Grant the roles/owner role to each business unit's administrators at the organization level to simplify management
Why it's wrong here
Organization-level Owner grants broad control over all resources and billing, violating least privilege and undermining separation between business units. It also makes centralized policy enforcement harder because administrators could alter or remove constraints, which is the opposite of the controlled governance the firm wants.
- ✓
Use a Shared VPC host project to centralize network administration while service projects host the workloads
Why this is correct
Shared VPC allows a host project to own the VPC network and subnets while service projects attach their resources to those subnets. Network administration stays centralized with the host project's administrators, and service project teams can deploy workloads without managing network topology, matching the separation and centralization requirements.
- ✗
Place all projects directly under the organization node and manage permissions only at the project level
Why it's wrong here
Flat placement under the organization node removes the inheritance layer that folders provide, forcing administrators to configure IAM and policy on each project individually. This increases the risk of drift and makes it harder to enforce consistent controls, which conflicts with the goal of centralized governance across business units.
- ✗
Create a separate organization node for each business unit to isolate billing and IAM
Why it's wrong here
A Google Cloud organization node is tied to a single Workspace or Cloud Identity domain and cannot be arbitrarily created per business unit. Multiple organizations would fragment billing, IAM, and policy management rather than centralize them, so this approach contradicts the stated goal of consistent cross-unit governance.
- ✓
Create a folder per business unit under the organization node and apply IAM policies and Organization Policy constraints at the folder level
Why this is correct
Folders under the organization node let administrators delegate administration per business unit while applying IAM and Organization Policy constraints that are inherited by all descendant projects. This provides consistent governance and separation without duplicating policy in every project, directly addressing the requirement for centralized controls across many projects.
Visual reference
Go deeper
Related to this question
Learn chapter
Data Migration and Transfer Services
Key term
CAN
A CAN (Controller Area Network) is a robust vehicle bus standard designed to allow microcontrollers and devices to communicate with each other without a host computer.
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.