Courseiva

Google PCA Design and plan a cloud solution architecture Practice Question

A healthcare company is planning a Google Cloud landing zone for a new regulated workload. They must enforce organization-wide guardrails, centralize billing visibility, and give each business unit autonomy over its own projects. The security team needs to apply policies that cannot be overridden by project owners. Which two design choices should you recommend? (Choose two.)

⚠ Common exam trap

The trap here is equating business unit autonomy with granting organization-wide or billing administrator roles, when autonomy should be delegated through folder-scoped IAM and inherited policies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Cloud Billing export to BigQuery and create a shared log sink to a central project for audit and cost analysis.

A folder hierarchy lets the company apply organization policies that inherit to all descendant projects and cannot be overridden by project owners, satisfying the guardrail requirement. Exporting billing data to BigQuery and centralizing logs provide the centralized billing and audit visibility. Granting broad roles like Billing Account Administrator or Organization Administrator, or flattening the hierarchy, undermines centralized control and least privilege.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable Cloud Billing export to BigQuery and create a shared log sink to a central project for audit and cost analysis.

    Why this is correct

    Exporting billing data to BigQuery enables centralized cost analysis and chargeback reporting across all business units. A shared log sink to a central project aggregates audit logs for compliance and security monitoring. Together these provide the centralized visibility the company needs while allowing business units to manage their own projects under the folder hierarchy.

  • ✗

    Place all projects directly under the organization root and rely on project-level IAM to enforce security policies.

    Why it's wrong here

    Placing projects directly under the root removes the folder layer that enables inherited, non-overridable organization policies, and it makes delegated administration harder to manage at scale. Project-level IAM alone cannot enforce constraints that project owners might change. This option fails because it does not provide the organization-wide guardrails or the structured delegation the scenario requires.

  • ✓

    Create a folder hierarchy under the organization that mirrors business units, and apply organization policies at the folder level.

    Why this is correct

    Organization policies applied at a folder inherit down to all projects beneath it, and project owners cannot override them, which enforces the required guardrails. A folder hierarchy that mirrors business units also supports delegated administration and keeps the structure aligned with how the company operates. This directly satisfies the need for non-overridable, organization-wide policy enforcement.

  • ✗

    Give each business unit the Organization Administrator role so they can manage their own projects independently.

    Why it's wrong here

    Organization Administrator grants full control over the entire organization, including IAM policies, folders, and billing, so it destroys the guardrails and centralized control the company requires. Autonomy should be delegated through folder-level IAM roles such as Folder Admin, not by granting organization-wide admin. This option fails because it violates least privilege and the requirement for non-overridable security policies.

  • ✗

    Grant each business unit the Billing Account Administrator role on the shared billing account to give them billing autonomy.

    Why it's wrong here

    Billing Account Administrator allows a user to change billing settings, link projects, and view all costs on that billing account, which breaks centralized billing visibility and least privilege. Business units should instead be given Billing Account User or Billing Account Viewer scoped appropriately. This option fails because it grants excessive permissions that undermine the centralized billing requirement.

About these practice questions

This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.