Google PCA Design for security and compliance Practice Question
A healthcare company stores patient records in Cloud Storage buckets across several projects. Compliance auditors require that no object can ever be made publicly readable, even by a project Owner, and that any attempt to do so must be blocked centrally. The security team must enforce this without breaking existing application access. What should they do?
⚠ Common exam trap
The trap here is assuming that removing broad IAM roles or enabling uniform bucket-level access prevents public exposure, when only the public access prevention organization policy constraint actively blocks public grants.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an organization policy with the `storage.publicAccessPrevention` constraint set to enforced at the organization node.
The `storage.publicAccessPrevention` organization policy constraint is the only mechanism here that centrally and preventively blocks public access grants at the organization level, regardless of a principal's project-level permissions. Because organization policies are inherited, enforcing it once at the org node covers all current and future projects while leaving legitimate IAM bindings untouched.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an organization policy with the `storage.publicAccessPrevention` constraint set to enforced at the organization node.
Why this is correct
The `storage.publicAccessPrevention` organization policy constraint, enforced at the organization node, blocks any attempt to grant `allUsers` or `allAuthenticatedUsers` access to Cloud Storage buckets and objects, including by project Owners. Because it is inherited downward, it protects every project without altering existing IAM bindings for legitimate service accounts and users, so application access continues to work.
- ✗
Grant the `roles/storage.admin` role only to a dedicated security group and remove it from all project Owners.
Why it's wrong here
Removing `roles/storage.admin` from project Owners reduces who can change bucket IAM, but it does not prevent a future misconfiguration or a differently privileged principal from granting `allUsers` access. It also risks breaking legitimate administrative workflows and does not provide the centralized, auditable guarantee the auditors demand. This is access reduction, not a preventive guardrail.
- ✗
Enable uniform bucket-level access on every bucket and rely on IAM conditions to deny public members.
Why it's wrong here
Uniform bucket-level access only disables object-level ACLs; it does not stop an administrator from binding `allUsers` to a bucket-level IAM role. IAM deny policies with conditions could help, but they are not automatically applied across all projects and require explicit maintenance. This approach leaves a gap because a permissive IAM binding remains possible.
- ✗
Configure VPC Service Controls perimeters around each project to restrict access to Cloud Storage.
Why it's wrong here
VPC Service Controls perimeters restrict access based on network origin and identity context, protecting against data exfiltration, but they do not prevent a bucket from being made publicly readable. Public internet users outside the perimeter are blocked from the API, yet the bucket's IAM policy would still list `allUsers`, which violates the auditors' explicit requirement.
Go deeper
Related to this question
Learn chapter
Identity and Access Management (IAM)
Key term
Project
A project is a temporary endeavor with a defined beginning and end, undertaken to create a unique product, service, or result, managed through specific processes in IT environments.
Key term
Cloud storage
Cloud storage is a service that lets you save data on remote servers accessed over the internet instead of on your computer's hard drive.
About these practice questions
Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.