Google PCA Design and plan a cloud solution architecture Practice Question
A healthcare analytics company is designing the Google Cloud landing zone for a new HIPAA-regulated workload. The security team requires that no project in the organization can enable a public Cloud Storage bucket by accident, and that all data-at-rest in BigQuery is encrypted with keys the company rotates on its own schedule. Which two design decisions should the architect include? (Choose two.)
⚠ Common exam trap
The trap here is treating uniform bucket-level access as a public-access control, when it only removes object ACLs and still permits allUsers IAM bindings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Cloud KMS keyring in each region where BigQuery datasets reside, and set a default CMEK on each dataset
Two controls map directly to the stated requirements. The storage.publicAccessPrevention organization policy is a preventive, inherited guardrail that blocks public bucket grants anywhere in the organization. A default CMEK on each BigQuery dataset, with regional keyrings, gives the company control over the rotation schedule and key lifecycle. Uniform bucket-level access, Google-managed keys, and narrow role grants do not enforce either requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a Cloud KMS keyring in each region where BigQuery datasets reside, and set a default CMEK on each dataset
Why this is correct
BigQuery datasets accept a default customer-managed encryption key, so every table created in the dataset is encrypted with that key without per-table configuration. Placing keyrings in the same regions as the datasets satisfies data-residency expectations, and the company controls rotation schedule and key destruction through Cloud KMS.
- ✗
Enable uniform bucket-level access on every bucket through an organization policy constraint
Why it's wrong here
Uniform bucket-level access simplifies IAM by disabling object ACLs, but it does not prevent a bucket from being made public, because an IAM binding to allUsers is still permitted. It is a useful hygiene control but does not satisfy the explicit requirement to block public buckets across the organization.
- ✗
Grant the Storage Admin role only to a small group of platform engineers at the organization level
Why it's wrong here
Limiting Storage Admin reduces the number of people who could create a public bucket, but it is a procedural control, not a preventive one. Any future role binding or a project-level grant could still allow public access, and this option does nothing for BigQuery key rotation, so it fails both stated requirements.
- ✗
Use Google-managed encryption keys for BigQuery and rely on the default rotation performed by Google
Why it's wrong here
Google-managed encryption keys protect data at rest by default, but the company cannot set the rotation schedule or revoke the key, so the requirement for company-controlled rotation is not met. This option also provides no protection against accidental public buckets, leaving both stated security objectives unaddressed.
- ✓
Apply an organization policy constraint with storage.publicAccessPrevention enforced at the organization node
Why this is correct
The storage.publicAccessPrevention constraint, enforced at the organization node, blocks any project or bucket from granting allUsers or allAuthenticatedUsers access, which is exactly the guardrail against accidental public buckets. Organization policies are inherited and cannot be overridden by project owners unless they hold the org policy admin role, giving centralized enforcement.
Go deeper
Related to this question
Learn chapter
Identity and Access Management (IAM)
Key term
Data
Data is raw, unprocessed information, like numbers, words, or measurements, that can be stored, processed, and analyzed by computers.
Key term
Cloud storage
Cloud storage is a service that lets you save data on remote servers accessed over the internet instead of on your computer's hard drive.
About these practice questions
This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.