Courseiva

Google PCA Design for security and compliance Practice Question

A financial services firm stores sensitive customer records in Cloud Storage and must ensure that only identities in its corporate domain can read the objects, that no object can ever be made publicly accessible, and that access decisions are evaluated centrally. The firm wants the least administrative overhead while keeping these guarantees across many buckets created by different teams. What should the architect implement?

⚠ Common exam trap

The trap here is treating encryption as an access control when key possession does not grant or deny read permission on a Cloud Storage object.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply an organization policy constraint with the storage.publicAccessPrevention enforced across the organization, and grant bucket access through IAM conditions that restrict principals to the corporate domain.

The firm needs a preventive control that no team can bypass and an access model that is scoped to the corporate domain. Enforcing the public access prevention organization policy makes the no-public-access guarantee inherited and non-overridable at lower levels. IAM conditions limiting principals to the corporate domain keep read access inside the firm while allowing centralized administration. This pairing addresses both the exposure guarantee and the identity restriction with minimal per-bucket work.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use a customer-managed encryption key for every bucket and grant roles/storage.objectAdmin only to a single service account that proxies all reads for the corporate domain.

    Why it's wrong here

    Encryption keys do not control who can read an object if the reader has the appropriate IAM permission on the bucket. Funneling all reads through a single service account creates a bottleneck and a single point of compromise while still not preventing a bucket owner from granting public access later. It also adds significant administrative overhead, contrary to the requirement.

  • ✗

    Enable VPC Service Controls with a service perimeter around the projects and grant roles/storage.objectViewer to the domain using a Google Group.

    Why it's wrong here

    VPC Service Controls restrict data movement across a perimeter, but they do not by themselves prevent an object from being made public through IAM or ACLs. A Google Group does help manage domain members, yet membership can be extended to external accounts and there is no automatic domain-only enforcement. This combination does not meet the public-access and domain-restriction guarantees.

  • ✓

    Apply an organization policy constraint with the storage.publicAccessPrevention enforced across the organization, and grant bucket access through IAM conditions that restrict principals to the corporate domain.

    Why this is correct

    Organization policy constraints enforce the public access prevention setting across every project and bucket beneath the organization, so no team can override it. IAM conditions on role bindings can restrict access to principals whose email matches the corporate domain, letting the firm centralize access decisions without per-bucket ACL management. Together these controls meet the guarantee and minimize ongoing administration across many teams.

  • ✗

    Set each bucket's default object ACL to private and rely on Cloud Storage's default uniform bucket-level access to block public reads, while granting roles/storage.objectViewer to all authenticated users.

    Why it's wrong here

    Granting object viewer to all authenticated users allows any Google account outside the corporate domain to read objects, directly violating the domain restriction. Setting ACLs per bucket also does not prevent a future bucket from being misconfigured, and uniform bucket-level access alone does not block public exposure unless public access prevention is explicitly enforced. This approach fails the central guarantee.

About these practice questions

Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.