Google PCA Design for security and compliance Practice Question
A financial services firm runs a regulated workload in a Google Cloud organization. Compliance requires that no resource in any project can be created outside a defined set of approved regions, and that violations are blocked before resource creation rather than reported afterward. The organization has many projects and new projects are created frequently. Which approach should the architect implement?
⚠ Common exam trap
Candidates often confuse VPC Service Controls, which govern data access and exfiltration, with organization policies, which govern resource configuration and placement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an organization policy with the location restriction constraint (constraints/gcp.resourceLocations) applied at the organization node
Organization policies are preventive controls that inherit through the resource hierarchy, so a location restriction set at the organization node automatically applies to every existing and future project. VPC Service Controls, VPC peering constraints, and asset-based remediation either govern the wrong thing or act only after the fact, so none of them blocks resource creation in a prohibited region.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy an organization policy using compute.restrictVpcPeering and rely on network topology to limit regions
Why it's wrong here
The restrictVpcPeering constraint governs which VPC networks may peer with each other; it has no relationship to the physical region in which resources are created. It cannot block a developer from launching a Compute Engine instance in a prohibited region, so it fails the stated compliance requirement.
- ✗
Enable VPC Service Controls perimeters around each project and restrict egress to unapproved regions
Why it's wrong here
VPC Service Controls create a security perimeter that limits data access and exfiltration across service boundaries, but they do not prevent resource creation in an unapproved region. A perimeter governs who can reach data, not where compute or storage resources may be provisioned, so it does not satisfy the location constraint.
- ✗
Write a Cloud Asset Inventory feed that triggers a Cloud Function to delete non-compliant resources
Why it's wrong here
Asset Inventory plus a remediation function is a detective and corrective control that acts after a resource already exists. The requirement explicitly states violations must be blocked before resource creation, so post-hoc deletion leaves a window where regulated data could be created in an unapproved location.
- ✓
Create an organization policy with the location restriction constraint (constraints/gcp.resourceLocations) applied at the organization node
Why this is correct
An organization policy using the location restriction constraint inherits down the resource hierarchy, so every current and future project in the organization is covered without per-project configuration. It enforces the allowed regions at resource-creation time, which is exactly the preventive control the compliance team requires rather than a detective control.
Go deeper
Related to this question
Learn chapter
Security Best Practices and Compliance
Key term
VPC
A Virtual Private Cloud (VPC) is a logically isolated section of a cloud provider's network where you can launch and manage resources like servers and databases with complete control over IP addressing, subnets, route tables, and security.
Key term
VPC peering
VPC peering is a direct network connection between two virtual private clouds that allows them to communicate using private IP addresses as if they were part of the same network.
About these practice questions
This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.