Courseiva

Google PCA Designing for Security and Compliance Practice Question

An organization runs workloads in multiple Google Cloud projects and wants a single, consistent way to detect and respond to threats such as compromised service accounts and anomalous API calls across all of them. The security operations team needs findings aggregated in one place and wants to reduce the effort of correlating events from Cloud Audit Logs, VPC Flow Logs, and Cloud DNS logs. Which Google Cloud service should the architect recommend?

⚠ Common exam trap

The trap here is assuming that log-based metrics, monitoring dashboards, or preventive perimeter controls provide built-in cross-project threat detection, which only Security Command Center Premium delivers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security Command Center with the Premium tier enabled at the organization level, using its built-in detectors and Event Threat Detection.

Security Command Center Premium is the centralized security posture and threat detection service for Google Cloud. Enabled at the organization level, it continuously evaluates resources across projects and Event Threat Detection consumes Cloud Audit Logs, VPC Flow Logs, and Cloud DNS logs to identify compromised service accounts, anomalous API calls, and similar threats, consolidating findings so the security operations team does not have to correlate sources manually.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VPC Service Controls perimeters around each project with access levels tied to the corporate network.

    Why it's wrong here

    VPC Service Controls define security perimeters that restrict data movement and mitigate exfiltration, but they are preventive controls rather than a detection and response platform. They do not produce aggregated threat findings or analyze audit, flow, and DNS logs for compromised accounts.

  • ✗

    Cloud Logging with log-based metrics and alerting policies that trigger when error rates exceed a threshold.

    Why it's wrong here

    Log-based metrics and alerting can detect patterns the team defines explicitly, but they do not provide built-in threat detectors for compromised service accounts or anomalous API behavior, nor do they aggregate findings into a unified risk view across projects. The team would have to author and maintain every detection rule manually.

  • ✓

    Security Command Center with the Premium tier enabled at the organization level, using its built-in detectors and Event Threat Detection.

    Why this is correct

    Security Command Center Premium aggregates findings at the organization level across all projects. Event Threat Detection analyzes Cloud Audit Logs, VPC Flow Logs, and Cloud DNS logs to surface issues like compromised service accounts and anomalous API activity, providing a single consolidated view and reducing manual correlation, which matches the stated need.

  • ✗

    Cloud Monitoring dashboards combined with uptime checks on each project's API endpoints.

    Why it's wrong here

    Cloud Monitoring and uptime checks measure availability and performance of endpoints; they are not threat detection tools. They cannot identify compromised credentials or suspicious API call sequences, and dashboards do not aggregate security findings, so this does not meet the detection and response objective.

About these practice questions

This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.