Google ACE Configuring Access and Security Practice Question
A company wants to implement a least-privilege security model for a service account that needs to read secrets from Secret Manager and publish messages to Pub/Sub. Which TWO IAM roles should be granted? (Choose TWO)
⚠ Common exam trap
ACE often tests the difference between viewer and accessor roles — candidates pick secretmanager.viewer thinking it allows reading the secret, but it only exposes metadata, not the payload.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
roles/pubsub.publisher
Option A, roles/pubsub.publisher, is correct because it grants exactly the permission needed to publish messages to a Pub/Sub topic (pubsub.topics.publish) without granting administrative capabilities, which fits the least-privilege requirement. Option C, roles/secretmanager.secretAccessor, is correct because it provides the minimal permission to access the payload of a secret (secretmanager.versions.access), which is precisely what the service account needs to read secrets. Option B, roles/secretmanager.viewer, is not appropriate because it allows viewing secret metadata but not accessing the secret payload, so it would not satisfy the read-secrets requirement. Option D, roles/pubsub.admin, is too broad since it grants full control over Pub/Sub resources, violating least privilege. Option E, roles/secretmanager.admin, is also overly permissive, granting full administrative control over Secret Manager rather than just read access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
roles/pubsub.publisher
Why this is correct
roles/pubsub.publisher is the correct least-privilege choice because it contains only the pubsub.topics.publish permission, which is exactly what a producer needs to send messages to a Pub/Sub topic. It does not grant permission to create, delete, or modify topics, subscribe, or manage IAM, so a compromised token from this service account could not reconfigure messaging infrastructure.
- ✗
roles/secretmanager.viewer
Why it's wrong here
roles/secretmanager.viewer is insufficient because it only allows listing secrets and viewing secret metadata such as labels, replication, and IAM policies, but not reading the actual secret versions. The Viewer role does not include the secretmanager.versions.access permission, so an application needing the real secret value would fail with a permission denied error.
- ✓
roles/secretmanager.secretAccessor
Why this is correct
roles/secretmanager.secretAccessor is purpose-built for reading secret payloads: it includes secretmanager.versions.access, the single exact permission required to retrieve the decrypted data from a secret version. It deliberately omits write, delete, and IAM-management permissions, making it the tightest viable role when an application only needs secret values.
- ✗
roles/pubsub.admin
Why it's wrong here
roles/pubsub.admin grants full control over the entire Pub/Sub service, including creating and deleting topics and subscriptions, seeking or deleting subscriptions, managing snapshots, and setting IAM policies. Using this role just to publish messages vastly exceeds minimum necessary access and could allow an attacker who compromises the credentials to destroy topics or eavesdrop by creating subscriptions.
- ✗
roles/secretmanager.admin
Why it's wrong here
roles/secretmanager.admin is a management role that can create, update, and delete secrets and versions, set IAM bindings, and enable or disable versions. Because it includes far more than the read access needed, it violates least privilege and introduces risk of accidental or malicious deletion or exfiltration of all secrets managed by the project.
Go deeper
Related to this question
Learn chapter
VPC Service Controls
Key term
Service
A service is a software component or system that performs a specific function and is available to be used by other programs or users over a network.
Key term
Service account
A service account is a special type of account used by an application or a virtual machine, rather than a human user, to authenticate and interact with cloud services and APIs securely.
About these practice questions
This ACE question is part of Courseiva's 775-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.