Google PCA Design and plan a cloud solution architecture Practice Question
A multinational retailer is planning its Google Cloud landing zone. Each of the company's business units must be able to create projects and manage billing independently, but the central platform team must retain the ability to enforce network and security guardrails across everything. The company also wants to minimize the number of distinct IAM policy bindings it maintains at the top of the hierarchy. Which two design choices should the architect make? (Choose two.)
⚠ Common exam trap
The trap here is solving delegation by granting a powerful organization-wide role instead of scoping permissions at a folder.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply organization policies such as constraints on allowed resource locations and external IP addresses at the organization node so they are inherited by all folders and projects
Delegating project creation and billing to folder-level roles gives each business unit autonomy while keeping the grant in one place per unit. Applying organization policies at the organization node enforces network and security guardrails through inheritance, so the central team controls every descendant without per-project work. Together these choices satisfy autonomy, central control, and a small number of top-level IAM bindings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Grant each business unit's administrators the Organization Administrator role so they can create projects anywhere in the hierarchy
Why it's wrong here
Organization Administrator is a powerful role that allows managing IAM policies and organization policies across the entire hierarchy, including other business units. Granting it to each unit would let one unit weaken guardrails or affect another unit's resources, defeating the central control requirement. It also enlarges the blast radius of any compromised account.
- ✗
Create every project directly under the organization node and attach a distinct billing account to each project for isolation
Why it's wrong here
Placing all projects directly under the organization node removes the folder layer that enables grouped, inherited IAM and organization policies. That forces administrators to bind roles project by project, increasing the number of policy bindings rather than minimizing them. One billing account per project also multiplies billing administration instead of simplifying it.
- ✓
Apply organization policies such as constraints on allowed resource locations and external IP addresses at the organization node so they are inherited by all folders and projects
Why this is correct
Organization policies applied at the organization node are inherited by every descendant folder and project, which enforces guardrails centrally without per-project configuration. This directly supports the requirement that the central platform team retains control while business units operate independently, and it avoids duplicating policy definitions across many projects.
- ✗
Use a shared VPC host project per business unit and grant the central team Compute Network Admin on each host project only
Why it's wrong here
Shared VPC centralizes network administration, which is useful, but it does not by itself give business units the ability to create projects, nor does it reduce IAM bindings at the top of the hierarchy. Relying on per-host-project role grants actually adds bindings. This addresses network topology rather than the delegated project creation and centralized guardrail requirements.
- ✓
Create a separate folder per business unit under the organization node and grant each business unit's administrators project creator and billing roles at the folder level
Why this is correct
Folders group projects by business unit and allow IAM policies and organization policies to be inherited downward. Granting project creator and billing roles at the folder level lets each unit self-serve without granting those permissions organization-wide. This concentrates administration at one node per unit and keeps the number of top-level bindings small, as the scenario requires.
Go deeper
Related to this question
Learn chapter
Billing, Budgets, and Cost Management
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
Key term
Project
A project is a temporary endeavor with a defined beginning and end, undertaken to create a unique product, service, or result, managed through specific processes in IT environments.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.