hardMultiple Select
Google ACE Practice Question: A developer needs to allow a CI/CD system to…
A developer needs to allow a CI/CD system to deploy applications to Cloud Run. The CI/CD system uses a service account. Which two roles should be granted to that service account?
⚠ Common exam trap
ACE often tests the distinction between roles needed to deploy (run.admin) versus roles needed to invoke (run.invoker) and the separate requirement for serviceAccountUser to act as the runtime service account.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
roles/iam.serviceAccountUser
Option D (roles/run.admin) is correct because deploying a new Cloud Run service or revision requires permissions such as run.services.create, run.services.update, and run.services.setIamPolicy, which are all contained in the Cloud Run Admin role. Option C (roles/iam.serviceAccountUser) is correct because Cloud Run deployments run under a runtime service account, and the deploying identity must have iam.serviceAccounts.actAs on that service account, which is granted by the Service Account User role. Option A (roles/cloudbuild.builds.builder) is not required since it only grants permissions to execute Cloud Build builds, not to deploy to Cloud Run. Option B (roles/run.invoker) only allows invoking a deployed Cloud Run service and does not permit deployment. Option E (roles/storage.objectViewer) only grants read access to Cloud Storage objects and is unrelated to Cloud Run deployment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
roles/cloudbuild.builds.builder
Why it's wrong here
roles/cloudbuild.builds.builder lets Cloud Build execute builds, covering image construction rather than Cloud Run service creation or revision updates. It is tempting because CI/CD pipelines do build images, and it would be correct where the service account runs Cloud Build jobs, not where it must deploy the resulting artefact to Cloud Run.
- ✗
roles/run.invoker
Why it's wrong here
roles/run.invoker grants permission to call or invoke a deployed Cloud Run service; it does not permit creating or updating services, so deployment fails. It is tempting because it is the standard Cloud Run role, and it would be correct when the service account must authenticate requests to a private service rather than deploy it.
- ✓
roles/iam.serviceAccountUser
Why this is correct
Granting roles/iam.serviceAccountUser lets the CI/CD service account impersonate the Cloud Run runtime service account, which Cloud Run requires when deploying a revision that runs as a specific identity. This satisfies the stem's need for the pipeline to act as that runtime identity during deployment.
- ✓
roles/run.admin
Why this is correct
Granting roles/run.admin lets the service account deploy and manage Cloud Run services and revisions, satisfying the CI/CD deployment requirement. It supplies the deploy permission the pipeline needs, though a narrower custom role could also work.
- ✗
roles/storage.objectViewer
Why it's wrong here
roles/storage.objectViewer grants read access to Cloud Storage objects, which supplies build context or artefacts but no Cloud Run deployment permissions. It is tempting because pipelines often pull source or layers from buckets, and it would be correct where the service account only needs to read objects during a build rather than create or update Cloud Run services.
Go deeper
Related to this question
Learn chapter
GCP Service Accounts and Workload Identity
Key term
IAM
Identity and Access Management (IAM) is a framework of policies and technologies that ensures the right individuals have the appropriate access to technology resources.
Key term
Service account
A service account is a special type of account used by an application or a virtual machine, rather than a human user, to authenticate and interact with cloud services and APIs securely.
About these practice questions
One of 775 original ACE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.