Courseiva

Google PCA Practice Question: Analysing and Optimising Technical and Business Processes

A healthcare company stores patient documents in Cloud Storage. Compliance requires that documents be retained for seven years and that no user, including administrators, can delete or overwrite them during that period. The company wants the simplest configuration that enforces this. What should the architect implement?

⚠ Common exam trap

The trap here is assuming that versioning or IAM restrictions provide immutability, when only a locked retention policy prevents both deletion and overwrite by any user.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set a bucket retention policy with a retention period of seven years and lock the policy.

The requirement is for immutable retention that even administrators cannot bypass. A bucket retention policy sets a minimum retention period during which objects cannot be deleted or replaced, and locking the policy makes it permanent. Object Versioning, IAM deny rules, and cross-bucket copies do not provide the same enforceable, time-bound guarantee against both deletion and overwrite.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Object Versioning and configure a lifecycle rule to delete noncurrent versions after seven years.

    Why it's wrong here

    Object Versioning preserves overwritten or deleted objects as noncurrent versions, but it does not prevent deletion of the current version or of all versions. A user with sufficient permissions can still delete objects or the entire bucket. The lifecycle rule only automates cleanup; it does not enforce immutability, so it fails the compliance requirement.

  • ✗

    Apply a bucket-level IAM policy that denies the storage.objects.delete permission to all users.

    Why it's wrong here

    An IAM deny policy can restrict deletion, but it does not prevent overwriting an object, which also destroys the original data. It also does not provide a time-bound guarantee, and administrators with permission to modify IAM could remove the restriction. This is weaker than a locked retention policy and does not meet the seven-year immutability requirement.

  • ✓

    Set a bucket retention policy with a retention period of seven years and lock the policy.

    Why this is correct

    A locked retention policy prevents objects from being deleted or overwritten until the retention period expires, and it cannot be removed or shortened once locked. This enforces immutability for seven years for all users, including administrators, with minimal configuration. It directly satisfies the compliance requirement without custom code or external tooling.

  • ✗

    Use a Cloud Storage transfer job to copy objects to a second bucket in a different region every day.

    Why it's wrong here

    Copying objects to another bucket provides redundancy but does not prevent deletion or modification in either bucket. The source objects can still be deleted or overwritten, and the copies are subject to the same permissions. This approach adds cost and complexity without enforcing immutability for seven years.

About these practice questions

This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.