certslothcertsloth
PCA/Topic 01

Google Cloud / Professional

Projects, Organizations, Billing and CLI

3 min read5 recall promptsReviewed 2026-10-09

Memory hook: Project contains; billing pays; IAM permits.

Must remember

The resource hierarchy places projects under folders and an organization where available. Projects contain resources, enabled APIs and quotas; billing accounts fund linked projects but are not simply their parent in the IAM hierarchy. Project names, unique IDs and numeric project numbers serve different purposes.

IAM allow policies can be inherited from ancestors; organization policies constrain allowed configurations rather than granting permissions. Cloud Identity/Google Workspace manages organizational identities and groups. Prefer group-based grants to many individual bindings, then review inherited permissions and applicable deny constraints.

Enable required service APIs in the intended project. A quota limits a metric such as resource count or API rate; requesting an increase does not guarantee physical capacity in a specific zone. Select regions for latency, availability, data-location requirements and product support, considering regional versus zonal resource scope.

Budgets alert; they are not automatically a hard spending cap. Export billing data for analysis, use labels and project organization for allocation, and review idle resources, retained disks, public addresses and network transfer. Linking billing and granting access to billing reports require appropriate billing permissions, distinct from workload administration.

gcloud config list and gcloud auth list inspect the active CLI configuration/identity. Named configurations help switch contexts; explicit --project, region and zone flags reduce ambiguity. Cloud Shell supplies a managed command environment but actions still use identity and authorization. Application Default Credentials used by libraries can differ from gcloud's active login: diagnose the actual caller.

Recall drill: explain why a user can administer a VM yet cannot view billing, or can view a project but cannot invoke an API that has not been enabled.

Choose under exam pressure

Requirement Choice and reason
Central identity administration Cloud Identity/Workspace groups with appropriate IAM grants.
Warn at a spend threshold A billing budget and notifications, plus a separate control process if needed.
Prevent prohibited resource configurations Organization policy constraints.

Traps

  • A budget is not a guaranteed automatic shutdown.
  • Changing the gcloud project does not rewrite every script’s explicit project flag.

Active recall

1. Is a billing account the IAM parent of a project?

No. Billing linkage and resource hierarchy are distinct.

2. What does API enablement do?

Makes a service available for use in that project, subject to permissions, quotas and configuration.

3. Why inspect Application Default Credentials separately?

Libraries may use a different identity from the active gcloud account.

4. What is a quota increase not a guarantee of?

Immediate physical capacity in the desired location.

5. Why prefer groups for many user grants?

They simplify lifecycle management and consistent review of access.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.