Google PCA Manage implementation of cloud architecture Practice Question
An organization wants to enforce that all Compute Engine VMs are created with specific disk encryption keys. Which policy mechanism should they use?
⚠ Common exam trap
A common mix-up: candidates confuse IAM permissions (who can do something) with Organization Policy constraints (what is allowed to be done), leading candidates to choose IAM roles instead of the correct policy mechanism.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Organization policies with constraints/compute.restrictDiskEncryptionKeyTypes
The Organization Policy constraint `constraints/compute.restrictDiskEncryptionKeyTypes` allows administrators to enforce that all Compute Engine VMs must use specific disk encryption key types (e.g., CMEK or CSEK). This policy is evaluated at resource creation time and blocks any VM that does not comply with the allowed key types, providing a preventive control rather than a reactive one.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Organization policies with constraints/compute.restrictDiskEncryptionKeyTypes
Why this is correct
Organization policies with `constraints/compute.restrictDiskEncryptionKeyTypes` enforce CMEK requirements at the resource hierarchy level, blocking VM creation that lacks customer-managed encryption keys. This satisfies the stem's constraint that all Compute Engine VMs must be created with specific disk encryption keys, applying prevention rather than detection.
- ✗
IAM roles with compute.diskEncryptionKey permissions
Why it's wrong here
IAM roles grant identities permission to supply encryption keys but cannot enforce that every VM creation includes one; an organisation policy constraint does. IAM roles are correct for controlling who may perform key-related actions, not for mandating resource configuration.
- ✗
VPC Service Controls
Why it's wrong here
VPC Service Controls builds a perimeter around API access to services, controlling data exfiltration rather than the parameters inside a VM creation request. It would be correct for restricting access to sensitive Google Cloud APIs from untrusted networks, not for mandating disk encryption keys.
- ✗
Cloud Scheduler to check compliance
Why it's wrong here
Cloud Scheduler only triggers jobs at defined times; it cannot inspect or block VM creation requests, so it cannot enforce key selection. It is tempting because scheduled compliance sweeps suit periodic auditing, but enforcement of creation-time parameters requires an Organization Policy constraint on Compute Engine.
Go deeper
Related to this question
Learn chapter
Resource Monitoring and Logging with Cloud Operations
Key term
Compute Engine
Compute Engine is Google Cloud's Infrastructure-as-a-Service (IaaS) offering that lets you create and run virtual machines on Google's infrastructure.
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.