Courseiva

Google PCA Design for security and compliance Practice Question

Which TWO of the following are valid methods to control access to Google Cloud resources using Identity and Access Management (IAM)?

⚠ Common exam trap

Google Cloud often tests the distinction between attaching a policy to a resource versus assigning a role to an identity, where candidates mistakenly think that attaching a policy to a user or service account is valid, when in fact policies are always attached to resources, not to identities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attach an IAM policy to an organization

Option A is correct because IAM policies can be attached at the organization node in the resource hierarchy, allowing centralized control over all projects, folders, and resources beneath it. Option B is correct because IAM policies can be attached to a project, which is a fundamental resource container in Google Cloud where allow policies bind principals to roles. Options C and E are incorrect because IAM policies are attached to resources (like organizations, folders, projects, and individual resources), not directly to users or service accounts; users and service accounts are principals that appear inside a policy binding. Option D is incorrect because IAM roles are not assigned directly to a user as a standalone object; instead, a role is granted to a principal through a policy binding on a resource.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Attach an IAM policy to an organization

    Why this is correct

    IAM policies can be attached at the organisation node, and these inherit downward to all folders, projects and resources beneath it. This satisfies centralised control across the entire resource hierarchy rather than a single project scope.

  • ✓

    Attach an IAM policy to a project

    Why this is correct

    IAM policies attached at the project level govern access to every resource contained within that project, and inherit to child resources. This satisfies scoping permissions to a defined project boundary rather than the whole organisation.

  • ✗

    Attach an IAM policy to a user

    Why it's wrong here

    IAM policies attach to resources, folders, projects or organisations — not directly to users; user access comes via roles granted through those policies or group membership. It is tempting because users are the obvious access subject, but Google Cloud's allow-policy model binds principals to resources, so this is not a valid method.

  • ✗

    Assign an IAM role directly to a user

    Why it's wrong here

    Assigning a role directly to a user is not a valid IAM method; IAM binds roles to principals via allow policies on resources, not direct user-role assignment. It tempts because per-user permissions feel intuitive, and it would fit scenarios using legacy systems or Microsoft Entra ID group-based licensing rather than Google Cloud IAM.

  • ✗

    Attach an IAM policy to a service account

    Why it's wrong here

    Attaching an IAM policy to a service account is invalid; policies attach to resources, while service accounts are principals that receive role bindings. It tempts because service accounts are central to workload identity, and this would be correct when granting a service account access to a resource via a binding.

About these practice questions

Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.