Topic module

IAM, Hierarchy and Data Security

Security questions test IAM, resource hierarchy, service accounts, separation of duties, KMS, Secret Manager, encryption, VPC Service Controls, and remote access.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for Google Professional Cloud Architect

Treat each item as an architecture tradeoff: identify business drivers, technical constraints, migration dependencies, security controls, reliability targets, and operating model.

Core concepts

Concept 1

IAM, Hierarchy and Data Security questions test Google Cloud architecture tradeoffs instead of isolated product recall.

Exam cue: Identify the business driver, workload shape, data path, security boundary, reliability target, and operations model.

Concept 2

The best answer maps business goals to technical requirements, Well-Architected pillars, service fit, security, cost, reliability, and operations.

Exam cue: Choose the Google Cloud pattern that satisfies the stated constraint with the least unnecessary custom operations.

Concept 3

Eliminate options that ignore migration dependencies, resource hierarchy, data movement, network boundaries, compliance, or operational ownership.

Exam cue: Prefer managed, observable, secure, resilient, cost-aware, and automatable designs when requirements support them.

Risk pitfalls and guardrails

Choosing a familiar product before reading the business and technical constraints.

Guardrail: Avoid answers that pick products before reading business needs, compliance, migration dependencies, reliability targets, or operations ownership.

Optimizing for one pillar while ignoring security, reliability, performance, cost, or sustainability.

Guardrail: Avoid answers that pick products before reading business needs, compliance, migration dependencies, reliability targets, or operations ownership.

Skipping migration, deployment, monitoring, or support implications in an architecture scenario.

Guardrail: Avoid answers that pick products before reading business needs, compliance, migration dependencies, reliability targets, or operations ownership.

Memory anchors

IAM Allow Policy

An IAM allow policy grants principals roles on resources at a selected scope.

Resource Hierarchy

The hierarchy organizes organizations, folders, projects, and resources for policy inheritance.

Service Account

A service account is an identity used by workloads and automation.

Separation of Duties

Separation of duties splits responsibilities to reduce fraud, error, and privilege concentration.

Cloud KMS

Cloud KMS creates and manages cryptographic keys for supported services and applications.

Secret Manager

Secret Manager stores, versions, and controls access to secrets.

VPC Service Controls

VPC Service Controls help reduce data exfiltration risk around supported Google Cloud services.

Identity Aware Proxy

Identity-Aware Proxy controls access to applications and VMs based on identity and context.

Workload Identity Federation

Workload Identity Federation lets external workloads access Google Cloud without long-lived service account keys.

Context Aware Access

Context-aware access uses request context such as device, location, and user attributes in access decisions.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

A company wants security policies to apply to every Google Cloud resource, billing boundaries by business unit, and isolated application lifecycles. Which hierarchy is most appropriate?

A policy is granted at the organization level. What should the architect assume about descendant folders and projects?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.