Courseiva

Google ACE Configuring Access and Security Practice Question

A developer needs to allow a Compute Engine instance to access a Cloud Storage bucket without using a service account key file. The instance runs in a project that has the necessary APIs enabled. What should the developer do?

⚠ Common exam trap

The trap here is assuming that network-level settings or default service accounts with broad roles are the right way to grant access, rather than using a dedicated service account with least privilege.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attach a service account to the instance and grant it the necessary IAM roles.

Attaching a service account to the instance allows the instance to obtain short-lived credentials from the metadata server, eliminating the need for key files. Granting that service account the necessary IAM roles ensures it has the required permissions to access the Cloud Storage bucket. This is the recommended secure and manageable approach for Compute Engine workloads.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the instance's default Compute Engine service account and grant it the Editor role.

    Why it's wrong here

    While the default Compute Engine service account can be used, granting it the Editor role violates least privilege and provides overly broad permissions. The default service account may also be disabled or have limited scopes. The best practice is to create a dedicated service account with only the required permissions, rather than relying on the default with excessive privileges.

  • ✗

    Create a service account key and store it on the instance's persistent disk.

    Why it's wrong here

    Storing a service account key on the instance's disk introduces a long-lived credential that can be exfiltrated if the instance is compromised. It also requires key rotation and management overhead. This approach contradicts the goal of avoiding key files and is not the recommended secure method for granting access to Cloud Storage from Compute Engine.

  • ✓

    Attach a service account to the instance and grant it the necessary IAM roles.

    Why this is correct

    Attaching a service account to a Compute Engine instance automatically provides the instance with credentials via the metadata server. The application can use the default credentials to authenticate to Google Cloud APIs. By granting the service account appropriate IAM roles, such as Storage Object Viewer, the instance gains access without managing any key files.

  • ✗

    Enable Cloud Storage API access on the instance's network interface.

    Why it's wrong here

    Enabling API access on a network interface is not a valid configuration for granting Cloud Storage permissions. Access to Google Cloud APIs is controlled by IAM and the instance's service account, not by network interface settings. This option misrepresents how authentication and authorization work for Google Cloud services.

About these practice questions

One of 775 original ACE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.