Courseiva

Google PCA Design and plan a cloud solution architecture Practice Question

A healthcare analytics company is designing the Google Cloud landing zone for a new HIPAA-regulated workload. The security team requires that no project in the organization can enable a public Cloud Storage bucket by accident, and that all data-at-rest in BigQuery is encrypted with keys the company rotates on its own schedule. Which two design decisions should the architect include? (Choose two.)

⚠ Common exam trap

The trap here is treating uniform bucket-level access as a public-access control, when it only removes object ACLs and still permits allUsers IAM bindings.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Cloud KMS keyring in each region where BigQuery datasets reside, and set a default CMEK on each dataset

Two controls map directly to the stated requirements. The storage.publicAccessPrevention organization policy is a preventive, inherited guardrail that blocks public bucket grants anywhere in the organization. A default CMEK on each BigQuery dataset, with regional keyrings, gives the company control over the rotation schedule and key lifecycle. Uniform bucket-level access, Google-managed keys, and narrow role grants do not enforce either requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a Cloud KMS keyring in each region where BigQuery datasets reside, and set a default CMEK on each dataset

    Why this is correct

    BigQuery datasets accept a default customer-managed encryption key, so every table created in the dataset is encrypted with that key without per-table configuration. Placing keyrings in the same regions as the datasets satisfies data-residency expectations, and the company controls rotation schedule and key destruction through Cloud KMS.

  • ✗

    Enable uniform bucket-level access on every bucket through an organization policy constraint

    Why it's wrong here

    Uniform bucket-level access simplifies IAM by disabling object ACLs, but it does not prevent a bucket from being made public, because an IAM binding to allUsers is still permitted. It is a useful hygiene control but does not satisfy the explicit requirement to block public buckets across the organization.

  • ✗

    Grant the Storage Admin role only to a small group of platform engineers at the organization level

    Why it's wrong here

    Limiting Storage Admin reduces the number of people who could create a public bucket, but it is a procedural control, not a preventive one. Any future role binding or a project-level grant could still allow public access, and this option does nothing for BigQuery key rotation, so it fails both stated requirements.

  • ✗

    Use Google-managed encryption keys for BigQuery and rely on the default rotation performed by Google

    Why it's wrong here

    Google-managed encryption keys protect data at rest by default, but the company cannot set the rotation schedule or revoke the key, so the requirement for company-controlled rotation is not met. This option also provides no protection against accidental public buckets, leaving both stated security objectives unaddressed.

  • ✓

    Apply an organization policy constraint with storage.publicAccessPrevention enforced at the organization node

    Why this is correct

    The storage.publicAccessPrevention constraint, enforced at the organization node, blocks any project or bucket from granting allUsers or allAuthenticatedUsers access, which is exactly the guardrail against accidental public buckets. Organization policies are inherited and cannot be overridden by project owners unless they hold the org policy admin role, giving centralized enforcement.

About these practice questions

This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.