Courseiva

Google PCA Design and plan a cloud solution architecture Practice Question

A multinational retailer is planning its Google Cloud landing zone. Each of the company's business units must be able to create projects and manage billing independently, but the central platform team must retain the ability to enforce network and security guardrails across everything. The company also wants to minimize the number of distinct IAM policy bindings it maintains at the top of the hierarchy. Which two design choices should the architect make? (Choose two.)

⚠ Common exam trap

The trap here is solving delegation by granting a powerful organization-wide role instead of scoping permissions at a folder.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply organization policies such as constraints on allowed resource locations and external IP addresses at the organization node so they are inherited by all folders and projects

Delegating project creation and billing to folder-level roles gives each business unit autonomy while keeping the grant in one place per unit. Applying organization policies at the organization node enforces network and security guardrails through inheritance, so the central team controls every descendant without per-project work. Together these choices satisfy autonomy, central control, and a small number of top-level IAM bindings.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Grant each business unit's administrators the Organization Administrator role so they can create projects anywhere in the hierarchy

    Why it's wrong here

    Organization Administrator is a powerful role that allows managing IAM policies and organization policies across the entire hierarchy, including other business units. Granting it to each unit would let one unit weaken guardrails or affect another unit's resources, defeating the central control requirement. It also enlarges the blast radius of any compromised account.

  • ✗

    Create every project directly under the organization node and attach a distinct billing account to each project for isolation

    Why it's wrong here

    Placing all projects directly under the organization node removes the folder layer that enables grouped, inherited IAM and organization policies. That forces administrators to bind roles project by project, increasing the number of policy bindings rather than minimizing them. One billing account per project also multiplies billing administration instead of simplifying it.

  • ✓

    Apply organization policies such as constraints on allowed resource locations and external IP addresses at the organization node so they are inherited by all folders and projects

    Why this is correct

    Organization policies applied at the organization node are inherited by every descendant folder and project, which enforces guardrails centrally without per-project configuration. This directly supports the requirement that the central platform team retains control while business units operate independently, and it avoids duplicating policy definitions across many projects.

  • ✗

    Use a shared VPC host project per business unit and grant the central team Compute Network Admin on each host project only

    Why it's wrong here

    Shared VPC centralizes network administration, which is useful, but it does not by itself give business units the ability to create projects, nor does it reduce IAM bindings at the top of the hierarchy. Relying on per-host-project role grants actually adds bindings. This addresses network topology rather than the delegated project creation and centralized guardrail requirements.

  • ✓

    Create a separate folder per business unit under the organization node and grant each business unit's administrators project creator and billing roles at the folder level

    Why this is correct

    Folders group projects by business unit and allow IAM policies and organization policies to be inherited downward. Granting project creator and billing roles at the folder level lets each unit self-serve without granting those permissions organization-wide. This concentrates administration at one node per unit and keeps the number of top-level bindings small, as the scenario requires.

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.