Google PCA Designing for Security and Compliance Practice Question
A multinational corporation needs to ensure that data stored in Cloud Storage buckets in their Google Cloud organization cannot be accessed from outside their corporate network, even if IAM policies are misconfigured. They want to enforce this at the organization level with minimal administrative overhead. What should they do?
⚠ Common exam trap
The trap here is assuming that IAM Conditions or public access prevention alone can enforce network-based access control at scale.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a VPC Service Controls perimeter that includes the Cloud Storage service and the projects containing the buckets, and configure access levels to allow only corporate IP ranges.
VPC Service Controls provide a centralized, organization-level security perimeter that prevents access to Cloud Storage from outside authorized networks, even if IAM policies are misconfigured. By defining access levels based on corporate IP ranges, the organization can ensure that only requests from the corporate network are allowed. This is the most effective and least administrative approach compared to per-binding IAM Conditions or bucket-level constraints.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a VPC Service Controls perimeter that includes the Cloud Storage service and the projects containing the buckets, and configure access levels to allow only corporate IP ranges.
Why this is correct
VPC Service Controls create a security perimeter around Google Cloud services, preventing data exfiltration even if IAM is misconfigured. By including Cloud Storage and configuring access levels based on corporate IP ranges, access from outside the network is blocked. This is enforced at the organization level and requires minimal per-project configuration, meeting the requirement for centralized control.
- ✗
Enable Cloud Armor security policies on all Cloud Storage buckets to block external IPs.
Why it's wrong here
Cloud Armor is used with load balancers to protect web applications, not with Cloud Storage buckets. It cannot be directly attached to Cloud Storage. Therefore, this option is not technically feasible. Cloud Armor does not provide network-level access control for storage services. The requirement needs a service perimeter, not a WAF.
- ✗
Use IAM Conditions on all Cloud Storage IAM bindings to allow access only from corporate IP ranges.
Why it's wrong here
IAM Conditions can restrict access based on IP address, but they must be applied to each IAM binding individually. This creates significant administrative overhead and is prone to misconfiguration. It does not provide a centralized organization-level enforcement mechanism. If a new binding is added without the condition, access could be granted from anywhere. VPC Service Controls provide a stronger, centralized perimeter.
- ✗
Apply an organization policy constraint `storage.publicAccessPrevention` to all buckets.
Why it's wrong here
`storage.publicAccessPrevention` prevents buckets from being made public, but it does not restrict access to specific networks. An IAM misconfiguration that grants access to a user outside the corporate network would still allow access. This constraint addresses public exposure, not network-based access control. It does not meet the requirement to block access from outside the corporate network.
Go deeper
Related to this question
Learn chapter
Data Migration and Transfer Services
Key term
Data
Data is raw, unprocessed information, like numbers, words, or measurements, that can be stored, processed, and analyzed by computers.
Key term
VPC Service Controls
VPC Service Controls is a Google Cloud security feature that protects the data of managed services by defining perimeters that prevent data exfiltration and unauthorized access across public networks.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.