Courseiva

Google PCA Practice Question: Analyze and optimize technical and business processes

A startup is deploying a new web application on Google Cloud. They want to ensure that their development, staging, and production environments are isolated from each other for security and billing purposes. They also want to apply different IAM policies per environment. Which Google Cloud resource hierarchy structure should the architect recommend?

⚠ Common exam trap

Test-takers frequently confuse network isolation or labeling with full environment isolation, which requires separate projects and folder-level IAM policies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a separate folder for each environment under the organization node, and place projects within those folders.

Using folders under the organization node allows you to group projects by environment and apply distinct IAM policies at the folder level. This provides both security isolation and separate billing, as each project can have its own billing account. It is the standard Google Cloud best practice for multi-environment setups.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a single project and use labels to separate environments.

    Why it's wrong here

    Labels are for metadata and billing attribution, not for security isolation or IAM separation. A single project would share IAM policies and quotas across all environments, which violates the requirement for isolation. This approach does not provide the necessary security boundaries.

  • ✓

    Create a separate folder for each environment under the organization node, and place projects within those folders.

    Why this is correct

    Folders allow you to group projects and apply IAM policies at the folder level, which are inherited by all projects within. This provides isolation between environments and enables separate billing and security controls. It is the recommended way to structure a Google Cloud organization for multiple environments.

  • ✗

    Create a separate organization for each environment.

    Why it's wrong here

    A Google Cloud organization is tied to a single identity domain, such as a Workspace or Cloud Identity account. Creating multiple organizations is complex, often requires multiple domains, and is not necessary for environment isolation. It adds administrative overhead without benefits for this scenario.

  • ✗

    Create a single project and use separate VPC networks for each environment.

    Why it's wrong here

    Separate VPC networks provide network isolation but do not isolate IAM policies or billing. All environments would still share the same project-level IAM and quotas. This does not meet the requirement for different IAM policies per environment or separate billing.

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.