Drag or tap steps into the slots.
Google PCA Design for security and compliance Practice Question
Drag and drop the steps to set up a shared VPC in Google Cloud for a multi-project environment into the correct order.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Enable Shared VPC in the host project, then attach service projects, then grant IAM roles to service project users, then deploy resources in service projects.
The host project holds the VPC network. Service projects use the subnets. IAM roles control who can use the subnets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable Shared VPC in the host project, then attach service projects, then grant IAM roles to service project users, then deploy resources in service projects.
Why this is correct
This order follows the recommended Google Cloud process: first enable Shared VPC on the host project, then attach service projects, then grant IAM permissions (e.g., compute.networkUser) so service projects can use subnets, and finally deploy resources. It ensures prerequisites are met at each step.
- ✗
Attach service projects to the host project, then enable Shared VPC in the host project, then grant IAM roles, then deploy resources.
Why it's wrong here
This is incorrect because you cannot attach service projects before enabling Shared VPC on the host project. The host project must first have Shared VPC enabled to allow attachments.
- ✗
Enable Shared VPC in the host project, then grant IAM roles to service project users, then attach service projects, then deploy resources.
Why it's wrong here
This is incorrect because IAM roles for subnet usage should be granted after attaching service projects. Without attachment, the service project is not yet associated, and IAM roles may not apply correctly to the shared VPC resources.
- ✗
Enable Shared VPC in the host project, then attach service projects, then deploy resources in service projects, then grant IAM roles.
Why it's wrong here
This is incorrect because deploying resources before granting IAM roles would cause failures. Service projects need the compute.networkUser role (or equivalent) to use subnets. Without permissions, resource creation will be denied.
Visual reference
Go deeper
Related to this question
Learn chapter
IAM Policies, Service Accounts, and Auditing
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
Key term
VPC network
A Virtual Private Cloud (VPC) network is a logically isolated section of a public cloud provider's infrastructure where you can launch cloud resources in a virtual network that you define and control.
About these practice questions
Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.