Courseiva

Google PCA Designing for Security and Compliance Practice Question

A multinational corporation needs to comply with data residency requirements for EU customer data. They want to ensure that data stored in Cloud Storage, BigQuery, and Cloud SQL for EU customers never leaves the European Union, even by administrators. They also want to detect and remediate any configuration drift that could violate this policy. What should they implement?

⚠ Common exam trap

The trap here is assuming that VPC Service Controls or Cloud KMS key location enforces data residency, when only the 'constraints/gcp.resourceLocations' organization policy constraint restricts where resources can be physically created.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an organization policy constraint 'constraints/gcp.resourceLocations' with allowed values set to EU regions, and apply it at the organization level. Use Security Command Center to monitor for violations.

The organization policy constraint 'constraints/gcp.resourceLocations' is the native Google Cloud control that restricts resource creation to specified locations. Applied at the organization level, it ensures all projects inherit the EU-only restriction, preventing administrators from creating resources outside the EU. Security Command Center provides continuous monitoring and can detect any drift or violations, enabling remediation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy all workloads in EU regions and use a custom Terraform module that validates region parameters before deployment.

    Why it's wrong here

    A custom Terraform module can enforce region parameters for infrastructure deployed through Terraform, but it does not prevent manual or out-of-band resource creation in other regions. It also lacks continuous detection and remediation. This approach is not a comprehensive enforcement mechanism.

  • ✓

    Create an organization policy constraint 'constraints/gcp.resourceLocations' with allowed values set to EU regions, and apply it at the organization level. Use Security Command Center to monitor for violations.

    Why this is correct

    The organization policy constraint 'constraints/gcp.resourceLocations' restricts where resources can be created to specified locations, such as EU regions. Applying it at the organization level ensures all projects inherit the restriction. Security Command Center can detect violations and misconfigurations, providing the required monitoring and remediation capability.

  • ✗

    Configure VPC Service Controls perimeters around EU projects and use Access Context Manager to restrict access to EU-based identities.

    Why it's wrong here

    VPC Service Controls and Access Context Manager control access based on identity and network, not the physical location where data is stored. They do not prevent an administrator from creating a bucket in a US region. This option fails to enforce data residency at the resource creation level.

  • ✗

    Use Cloud KMS with EU-based key rings to encrypt all EU customer data, and rely on key location to enforce data residency.

    Why it's wrong here

    Cloud KMS key rings are regional, but encrypting data with an EU key does not prevent the encrypted data from being stored in a non-EU region. Key location controls where cryptographic operations occur, not where ciphertext resides. This option does not enforce data residency for storage services.

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.