Google PCA Design and plan a cloud solution architecture Practice Question
A healthcare analytics company is designing a BigQuery-based data warehouse that ingests patient records from multiple hospitals. Regulatory requirements mandate that queries never move data across regional boundaries and that only authorized analysts can access patient-identifiable columns. The architects want to enforce these controls at the platform level rather than relying on application code. Which combination of Google Cloud features should they design into the solution?
⚠ Common exam trap
The trap here is treating Cloud DLP as an access-control mechanism, when it only discovers and classifies sensitive data and does not restrict who can query specific columns.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
BigQuery dataset location set to a single region, VPC Service Controls perimeter around the project, and column-level security using policy tags in Data Catalog.
Data residency is enforced by pinning the BigQuery dataset to a single region. Preventing exfiltration and restricting access to authorized identities and networks is the role of VPC Service Controls. Column-level least privilege for patient-identifiable fields is achieved with policy tags in Data Catalog, which BigQuery enforces natively. This trio addresses residency, perimeter, and column-level authorization at the platform layer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
BigQuery dataset location set to a single region, authorized views that exclude patient-identifiable columns, and Cloud Armor security policies on the BigQuery API endpoint.
Why it's wrong here
Authorized views can restrict columns but are harder to manage at scale than policy tags and do not provide dynamic column-level masking. Cloud Armor protects HTTP(S) load-balanced applications, not the BigQuery API, so it does not enforce data access controls here. This design leaves gaps in centralized, auditable column-level security.
- ✗
BigQuery multi-region dataset, Cloud IAM basic roles for analysts, and Cloud DLP inspection jobs scheduled daily.
Why it's wrong here
A multi-region dataset can replicate data across regions, violating the no-cross-region mandate. Basic roles like BigQuery Data Viewer grant access to all columns, not just authorized ones, and Cloud DLP inspection only identifies sensitive data; it does not enforce column-level access. This combination fails both the residency and least-privilege requirements.
- ✗
BigQuery dataset location set to a single region, IAM conditions based on resource names, and customer-managed encryption keys in Cloud KMS.
Why it's wrong here
IAM conditions can restrict access to specific resources but cannot enforce column-level restrictions within a table. CMEK controls encryption key custody, not who can read which columns. Neither feature prevents an authorized table reader from seeing patient-identifiable columns, so the least-privilege requirement is unmet.
- ✓
BigQuery dataset location set to a single region, VPC Service Controls perimeter around the project, and column-level security using policy tags in Data Catalog.
Why this is correct
BigQuery dataset location pins data to a region, satisfying the no-cross-region requirement. A VPC Service Controls perimeter prevents data exfiltration and restricts access to only authorized networks and identities. Policy tags in Data Catalog enable column-level access control so only approved analysts can read patient-identifiable columns. Together these enforce controls at the platform level without application changes.
Go deeper
Related to this question
Learn chapter
Deployment Manager and Infrastructure as Code
Key term
CAN
A CAN (Controller Area Network) is a robust vehicle bus standard designed to allow microcontrollers and devices to communicate with each other without a host computer.
Key term
VPC Service Controls
VPC Service Controls is a Google Cloud security feature that protects the data of managed services by defining perimeters that prevent data exfiltration and unauthorized access across public networks.
About these practice questions
This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.