Courseiva

Google PCA Design for security and compliance Practice Question

A healthcare company stores patient records in Cloud Storage buckets across several projects. Compliance auditors require that no object can ever be made publicly readable, even by a project Owner, and that any attempt to do so must be blocked centrally. The security team must enforce this without breaking existing application access. What should they do?

⚠ Common exam trap

The trap here is assuming that removing broad IAM roles or enabling uniform bucket-level access prevents public exposure, when only the public access prevention organization policy constraint actively blocks public grants.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an organization policy with the `storage.publicAccessPrevention` constraint set to enforced at the organization node.

The `storage.publicAccessPrevention` organization policy constraint is the only mechanism here that centrally and preventively blocks public access grants at the organization level, regardless of a principal's project-level permissions. Because organization policies are inherited, enforcing it once at the org node covers all current and future projects while leaving legitimate IAM bindings untouched.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create an organization policy with the `storage.publicAccessPrevention` constraint set to enforced at the organization node.

    Why this is correct

    The `storage.publicAccessPrevention` organization policy constraint, enforced at the organization node, blocks any attempt to grant `allUsers` or `allAuthenticatedUsers` access to Cloud Storage buckets and objects, including by project Owners. Because it is inherited downward, it protects every project without altering existing IAM bindings for legitimate service accounts and users, so application access continues to work.

  • ✗

    Grant the `roles/storage.admin` role only to a dedicated security group and remove it from all project Owners.

    Why it's wrong here

    Removing `roles/storage.admin` from project Owners reduces who can change bucket IAM, but it does not prevent a future misconfiguration or a differently privileged principal from granting `allUsers` access. It also risks breaking legitimate administrative workflows and does not provide the centralized, auditable guarantee the auditors demand. This is access reduction, not a preventive guardrail.

  • ✗

    Enable uniform bucket-level access on every bucket and rely on IAM conditions to deny public members.

    Why it's wrong here

    Uniform bucket-level access only disables object-level ACLs; it does not stop an administrator from binding `allUsers` to a bucket-level IAM role. IAM deny policies with conditions could help, but they are not automatically applied across all projects and require explicit maintenance. This approach leaves a gap because a permissive IAM binding remains possible.

  • ✗

    Configure VPC Service Controls perimeters around each project to restrict access to Cloud Storage.

    Why it's wrong here

    VPC Service Controls perimeters restrict access based on network origin and identity context, protecting against data exfiltration, but they do not prevent a bucket from being made publicly readable. Public internet users outside the perimeter are blocked from the API, yet the bucket's IAM policy would still list `allUsers`, which violates the auditors' explicit requirement.

About these practice questions

Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.