Google ACE Configuring Access and Security Practice Question
A developer wants to create a service account for an application running on Compute Engine. The application needs to access Cloud Storage. What is the best practice for granting this access?
⚠ Common exam trap
A common mix-up: candidates confuse Workload Identity Federation (for external identities) with attaching a service account to a GCE instance, or they default to the built-in Compute Engine service account thinking it is 'the' service account for instances.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a service account, grant it the Cloud Storage roles, and attach it to the instance using the --service-account flag.
The best practice is to create a dedicated user-managed service account, grant it only the required Cloud Storage IAM roles (e.g., roles/storage.objectViewer), and attach it directly to the Compute Engine instance via the --service-account flag. This follows the principle of least privilege and avoids long-lived credentials. Attaching the service account to the instance lets the application obtain short-lived access tokens automatically from the metadata server.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Workload Identity Federation to grant access.
Why it's wrong here
Workload Identity Federation is designed for workloads running outside Google Cloud—such as on-premises or in another cloud—that need to impersonate a service account via OIDC or SAML identity tokens. A Compute Engine instance already has a native mechanism for attaching a service account directly to the VM, so using federation introduces an unnecessary external identity provider dependency and does not associate the account with the instance's metadata server. Therefore, it is incorrect for authorizing an application on GCE.
- ✓
Create a service account, grant it the Cloud Storage roles, and attach it to the instance using the --service-account flag.
Why this is correct
Creating a dedicated service account, granting it only the required Cloud Storage IAM roles such as roles/storage.objectViewer, and attaching it to the instance with the --service-account flag at creation time follows the principle of least privilege. The VM's metadata server then provides short-lived access tokens to the application, avoiding the need to manage or download any service account keys. This is the recommended, secure pattern for a GCE workload to access Cloud Storage with minimal permissions.
- ✗
Use the default Compute Engine service account and grant it Cloud Storage roles.
Why it's wrong here
The default Compute Engine service account is automatically attached to instances and often has the editor role on the project, granting broad and unintended permissions. Even if you additionally grant it specific Cloud Storage roles, the accumulated privileges far exceed what the application requires, increasing the blast radius if the instance is compromised. A dedicated service account scoped only to the necessary Cloud Storage roles is more secure and manageable than relying on the default account.
- ✗
Create a service account, download its key, and store it on the instance.
Why it's wrong here
Downloading a service account key and storing it on the instance is insecure because the key is a long-lived credential that must be securely stored, rotated, and protected; any attacker with disk access can exfiltrate it. In contrast, a service account attached to the instance uses the metadata server to issue short-lived OAuth2 tokens that are automatically rotated and never written to the filesystem. Thus, this option violates Google Cloud's best practices for VM credential management and should not be used.
Go deeper
Related to this question
Learn chapter
Cloud Storage Lifecycle Rules
Key term
Metadata server
A metadata server is a network-accessible service that provides configuration data, credentials, and instance-specific information to virtual machines running in a cloud environment like Google Cloud Platform.
Key term
Compute Engine
Compute Engine is Google Cloud's Infrastructure-as-a-Service (IaaS) offering that lets you create and run virtual machines on Google's infrastructure.
About these practice questions
One of 775 original ACE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.