Google PCA Practice Question: Managing and Provisioning a Solution Infrastructure
A security team wants to monitor and audit all changes to IAM policies in a Google Cloud organization. They need to set up real-time alerts when a new binding is added. Which THREE services should they combine to achieve this?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud Pub/Sub
Cloud Audit Logs (D) is correct because Admin Activity audit logs automatically record IAM policy changes such as SetIamPolicy events, which capture when a new binding is added, providing the source of truth for auditing and monitoring. Cloud Pub/Sub (B) is correct because a log sink can route those filtered audit log entries to a Pub/Sub topic in real time, decoupling log ingestion from downstream processing. Cloud Functions (C) is correct because a function can be triggered by messages published to that Pub/Sub topic to evaluate the new binding and send real-time alerts. Cloud Scheduler (A) is not needed since it only runs jobs on a time schedule and does not provide event-driven, real-time reaction to IAM changes. Cloud Storage (E) is not needed because it is object storage for retaining or archiving data, not a real-time alerting or event-processing service.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cloud Scheduler
Why it's wrong here
Cloud Scheduler triggers jobs on a cron timetable; it cannot read audit logs or evaluate IAM policy bindings, so no alert on a new binding is possible. It is tempting because scheduled polling of Cloud Logging is a valid pattern, but the trigger itself must be a Logging sink to Pub/Sub, not Scheduler.
- ✓
Cloud Pub/Sub
Why this is correct
Cloud Pub/Sub carries the audit log events onward, letting a subscriber receive IAM policy change notifications in real time. Combined with Cloud Logging log sinks and a notification channel, it delivers the alerting pipeline the security team requires for new bindings.
- ✓
Cloud Functions
Why this is correct
Cloud Functions supplies the serverless compute that receives the Pub/Sub notification and executes the alerting logic in real time. It satisfies the requirement to act on new IAM binding events, complementing Cloud Audit Logs for capture and Pub/Sub for transport.
- ✓
Cloud Audit Logs
Why this is correct
Cloud Audit Logs records Admin Activity entries for every IAM policy change, capturing the new binding as an auditable event. It satisfies the monitoring and audit requirement, and its log entries feed Pub/Sub so real-time alerts can be triggered.
- ✗
Cloud Storage
Why it's wrong here
Cloud Storage holds objects and has no role in capturing or alerting on IAM policy changes; audit logs and Pub/Sub notifications do that. It tempts because buckets commonly store exported logs, which would be the right choice when archiving audit data rather than triggering real-time alerts.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
Learn chapter
Data Migration and Transfer Services
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
Key term
Cloud Functions
Cloud Functions are serverless compute services that let you run single-purpose code in response to events without managing servers.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.