Courseiva

Google PCA Designing for Security and Compliance Practice Question

A multinational corporation needs to ensure that data stored in Cloud Storage buckets in their Google Cloud organization cannot be accessed from outside their corporate network, even if IAM policies are misconfigured. They want to enforce this at the organization level with minimal administrative overhead. What should they do?

⚠ Common exam trap

The trap here is assuming that IAM Conditions or public access prevention alone can enforce network-based access control at scale.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a VPC Service Controls perimeter that includes the Cloud Storage service and the projects containing the buckets, and configure access levels to allow only corporate IP ranges.

VPC Service Controls provide a centralized, organization-level security perimeter that prevents access to Cloud Storage from outside authorized networks, even if IAM policies are misconfigured. By defining access levels based on corporate IP ranges, the organization can ensure that only requests from the corporate network are allowed. This is the most effective and least administrative approach compared to per-binding IAM Conditions or bucket-level constraints.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a VPC Service Controls perimeter that includes the Cloud Storage service and the projects containing the buckets, and configure access levels to allow only corporate IP ranges.

    Why this is correct

    VPC Service Controls create a security perimeter around Google Cloud services, preventing data exfiltration even if IAM is misconfigured. By including Cloud Storage and configuring access levels based on corporate IP ranges, access from outside the network is blocked. This is enforced at the organization level and requires minimal per-project configuration, meeting the requirement for centralized control.

  • ✗

    Enable Cloud Armor security policies on all Cloud Storage buckets to block external IPs.

    Why it's wrong here

    Cloud Armor is used with load balancers to protect web applications, not with Cloud Storage buckets. It cannot be directly attached to Cloud Storage. Therefore, this option is not technically feasible. Cloud Armor does not provide network-level access control for storage services. The requirement needs a service perimeter, not a WAF.

  • ✗

    Use IAM Conditions on all Cloud Storage IAM bindings to allow access only from corporate IP ranges.

    Why it's wrong here

    IAM Conditions can restrict access based on IP address, but they must be applied to each IAM binding individually. This creates significant administrative overhead and is prone to misconfiguration. It does not provide a centralized organization-level enforcement mechanism. If a new binding is added without the condition, access could be granted from anywhere. VPC Service Controls provide a stronger, centralized perimeter.

  • ✗

    Apply an organization policy constraint `storage.publicAccessPrevention` to all buckets.

    Why it's wrong here

    `storage.publicAccessPrevention` prevents buckets from being made public, but it does not restrict access to specific networks. An IAM misconfiguration that grants access to a user outside the corporate network would still allow access. This constraint addresses public exposure, not network-based access control. It does not meet the requirement to block access from outside the corporate network.

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.