Google PCA Design for security and compliance Practice Question
Which TWO of the following are valid methods to control access to Google Cloud resources using Identity and Access Management (IAM)?
⚠ Common exam trap
Google Cloud often tests the distinction between attaching a policy to a resource versus assigning a role to an identity, where candidates mistakenly think that attaching a policy to a user or service account is valid, when in fact policies are always attached to resources, not to identities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attach an IAM policy to an organization
Option A is correct because IAM policies can be attached at the organization node in the resource hierarchy, allowing centralized control over all projects, folders, and resources beneath it. Option B is correct because IAM policies can be attached to a project, which is a fundamental resource container in Google Cloud where allow policies bind principals to roles. Options C and E are incorrect because IAM policies are attached to resources (like organizations, folders, projects, and individual resources), not directly to users or service accounts; users and service accounts are principals that appear inside a policy binding. Option D is incorrect because IAM roles are not assigned directly to a user as a standalone object; instead, a role is granted to a principal through a policy binding on a resource.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Attach an IAM policy to an organization
Why this is correct
IAM policies can be attached at the organisation node, and these inherit downward to all folders, projects and resources beneath it. This satisfies centralised control across the entire resource hierarchy rather than a single project scope.
- ✓
Attach an IAM policy to a project
Why this is correct
IAM policies attached at the project level govern access to every resource contained within that project, and inherit to child resources. This satisfies scoping permissions to a defined project boundary rather than the whole organisation.
- ✗
Attach an IAM policy to a user
Why it's wrong here
IAM policies attach to resources, folders, projects or organisations — not directly to users; user access comes via roles granted through those policies or group membership. It is tempting because users are the obvious access subject, but Google Cloud's allow-policy model binds principals to resources, so this is not a valid method.
- ✗
Assign an IAM role directly to a user
Why it's wrong here
Assigning a role directly to a user is not a valid IAM method; IAM binds roles to principals via allow policies on resources, not direct user-role assignment. It tempts because per-user permissions feel intuitive, and it would fit scenarios using legacy systems or Microsoft Entra ID group-based licensing rather than Google Cloud IAM.
- ✗
Attach an IAM policy to a service account
Why it's wrong here
Attaching an IAM policy to a service account is invalid; policies attach to resources, while service accounts are principals that receive role bindings. It tempts because service accounts are central to workload identity, and this would be correct when granting a service account access to a resource via a binding.
Go deeper
Related to this question
Learn chapter
Identity and Access Management (IAM)
Key term
CAN
A CAN (Controller Area Network) is a robust vehicle bus standard designed to allow microcontrollers and devices to communicate with each other without a host computer.
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
About these practice questions
Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.