Google PCA Design and plan a cloud solution architecture Practice Question
A healthcare company is planning a Google Cloud landing zone for a new regulated workload. They must enforce organization-wide guardrails, centralize billing visibility, and give each business unit autonomy over its own projects. The security team needs to apply policies that cannot be overridden by project owners. Which two design choices should you recommend? (Choose two.)
⚠ Common exam trap
The trap here is equating business unit autonomy with granting organization-wide or billing administrator roles, when autonomy should be delegated through folder-scoped IAM and inherited policies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Cloud Billing export to BigQuery and create a shared log sink to a central project for audit and cost analysis.
A folder hierarchy lets the company apply organization policies that inherit to all descendant projects and cannot be overridden by project owners, satisfying the guardrail requirement. Exporting billing data to BigQuery and centralizing logs provide the centralized billing and audit visibility. Granting broad roles like Billing Account Administrator or Organization Administrator, or flattening the hierarchy, undermines centralized control and least privilege.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable Cloud Billing export to BigQuery and create a shared log sink to a central project for audit and cost analysis.
Why this is correct
Exporting billing data to BigQuery enables centralized cost analysis and chargeback reporting across all business units. A shared log sink to a central project aggregates audit logs for compliance and security monitoring. Together these provide the centralized visibility the company needs while allowing business units to manage their own projects under the folder hierarchy.
- ✗
Place all projects directly under the organization root and rely on project-level IAM to enforce security policies.
Why it's wrong here
Placing projects directly under the root removes the folder layer that enables inherited, non-overridable organization policies, and it makes delegated administration harder to manage at scale. Project-level IAM alone cannot enforce constraints that project owners might change. This option fails because it does not provide the organization-wide guardrails or the structured delegation the scenario requires.
- ✓
Create a folder hierarchy under the organization that mirrors business units, and apply organization policies at the folder level.
Why this is correct
Organization policies applied at a folder inherit down to all projects beneath it, and project owners cannot override them, which enforces the required guardrails. A folder hierarchy that mirrors business units also supports delegated administration and keeps the structure aligned with how the company operates. This directly satisfies the need for non-overridable, organization-wide policy enforcement.
- ✗
Give each business unit the Organization Administrator role so they can manage their own projects independently.
Why it's wrong here
Organization Administrator grants full control over the entire organization, including IAM policies, folders, and billing, so it destroys the guardrails and centralized control the company requires. Autonomy should be delegated through folder-level IAM roles such as Folder Admin, not by granting organization-wide admin. This option fails because it violates least privilege and the requirement for non-overridable security policies.
- ✗
Grant each business unit the Billing Account Administrator role on the shared billing account to give them billing autonomy.
Why it's wrong here
Billing Account Administrator allows a user to change billing settings, link projects, and view all costs on that billing account, which breaks centralized billing visibility and least privilege. Business units should instead be given Billing Account User or Billing Account Viewer scoped appropriately. This option fails because it grants excessive permissions that undermine the centralized billing requirement.
Go deeper
Related to this question
Learn chapter
Cloud SQL and Managed Data Stores
Key term
Billing account
A billing account in Google Cloud is a container for all the charges generated by using cloud resources, linked to a payment method and used to track and pay for your usage.
Key term
BigQuery
BigQuery is a fully managed, serverless data warehouse on Google Cloud that lets you run fast SQL queries on massive datasets without managing any infrastructure.
About these practice questions
This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.