Google PCA: Organization Design, IAM and Cloud Governance — Study Guide

Part of the Google Professional Cloud Architect — Study Guide. Practice with verified answers in the Google exam hub, or take timed practice tests on ExamRoll.io.

Overview

Organization design, IAM, and governance establish the foundation on which all Google Cloud architectures run. Good designs create clear administrative boundaries, minimize blast radius, enable least privilege, control cost, and scale operationally across many teams and environments. Governance should emphasize guardrails over gates: automate defaults that are secure, measurable, and reversible, while delegating day-to-day control to the teams closest to the workload.

Resource Hierarchy and Identity Foundations

Google Cloud resources form a strict tree: Organization → Folders → Projects → Resources (for example, Compute Engine instances, buckets). IAM policies and Organization Policy constraints inherit down the tree.

Key design principles:

Identity sources:

Common failure modes and mitigations:

IAM Models, Roles, and Access Operations

Roles and bindings:

Least privilege and privilege elevation:

Deny policies and hazards:

Auditability and reviews:

Useful example (time-bounded, tag-scoped binding):

Financial Governance and Organization Policy Guardrails

Billing architecture:

Chargeback and cost visibility:

Budgets and anomaly detection:

Organization Policy constraints (secure-by-default):

Policy exception handling:

Example Organization Policy (YAML) to disable service account keys:

Landing Zones, Shared Services, Automation, and Operating Models

Landing zone:

Project factory:

Shared services and isolation:

Audit logging and governance automation:

Resource naming and tags:

Multi-team operations and delegated administration:

Practical Problem Scenario

Contoso Retail plans to onboard eight product teams to Google Cloud within three months. Each team needs prod and nonprod environments, isolated networking, centralized security logging, and cost accountability. The platform team must prevent service account key sprawl, restrict VM images, and enable time-bound elevated access for incident response.

Approach:

  1. Establish the hierarchy and folders
  1. Deploy a landing zone with Shared VPC
  1. Implement organization policy guardrails
  1. Stand up identity and groups
  1. Define IAM with least privilege and conditional elevation
  1. Build a project factory pipeline
  1. Centralize audit logging and access reviews
  1. Cost governance and alerts
  1. Workload identity and keyless automation
  1. Exception process and automation

Technical outcomes:


All domains · Compute

Practice these questions → · Timed practice on ExamRoll.io →

Pass the whole exam — not just this question

You found this answer. Get every verified question and explanation in one place, and save hours of prep. Free to start.

Pass your exam →

Browse Google →

Related guides

All-in-one access

One subscription. Every exam.

Every plan unlocks unlimited answer search, practice tests, AI explanations, and the full resource library — in 20+ languages.

Monthly
24.87
Just €0.83/day
Everything included:
  • Unlimited answer search
  • Unlimited practice tests
  • AI-powered explanations
  • Full resource library
  • 20+ languages
  • Weekly content updates
  • Rewards & referrals
  • Priority support
Start free trial

No credit card required*

Best value
12 months
179.87
Just €0.49/daySave 40%
Everything included:
  • Unlimited answer search
  • Unlimited practice tests
  • AI-powered explanations
  • Full resource library
  • 20+ languages
  • Weekly content updates
  • Rewards & referrals
  • Priority support
Start free trial

No credit card required*

✓ Free plan included · ✓ Cancel anytime · ✓ All plans unlock the full product