mediumMultiple Choice
Google ACE Practice Question: A DevOps engineer creates a service account for a…
A DevOps engineer creates a service account for a CI/CD pipeline. The pipeline needs to push container images to Artifact Registry. Which role grants the minimum required permission?
⚠ Common exam trap
Google Cloud often tests the misconception that Artifact Registry is just a wrapper around Cloud Storage, leading candidates to choose Storage Object Creator, but in reality, Artifact Registry uses its own IAM roles and does not expose the underlying bucket for direct permission assignment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Artifact Registry Writer
The Artifact Registry Writer role provides the minimal permissions needed to push container images to Artifact Registry, specifically the `artifactregistry.writer` permission. This role allows writing artifacts without granting broader administrative or read-only access, aligning with the principle of least privilege.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Artifact Registry Administrator
Why it's wrong here
Artifact Registry Administrator (roles/artifactregistry.admin) grants the full set of Artifact Registry permissions, including creation and deletion of repositories, editing repository settings, and managing IAM policies. For a CI/CD pipeline whose only job is to push artifacts to a pre-existing repository, this is far too broad and violates least privilege. An attacker or compromised build job with this role could delete repositories or grant themselves additional access, making the Writer role the safer choice.
- ✓
Artifact Registry Writer
Why this is correct
Artifact Registry Writer (roles/artifactregistry.writer) is the correct predefined role for a CI/CD pipeline that needs to push container images or packages. It grants exactly the permissions required to upload artifacts—e.g., artifactregistry.versions.create, artifactregistry.files.create, and artifactregistry.tags.create—without allowing destructive actions like deleting repositories or altering IAM policies. This aligns with least privilege because the pipeline only needs write access on an existing repository, not administrative control.
- ✗
Storage Object Creator on the underlying Cloud Storage bucket
Why it's wrong here
Storage Object Creator on the underlying Cloud Storage bucket is ineffective because Artifact Registry is a separate managed service with its own IAM permission model; it is not a direct wrapper around a user-visible GCS bucket. Even if artifact data is physically stored in Google-managed storage, the bucket is not accessible or modifiable by customers, and bucket-level IAM does not grant Artifact Registry API permissions such as artifactregistry.versions.create. A CI/CD pipeline pushing to Artifact Registry must have an Artifact Registry role, not a Cloud Storage role.
- ✗
Artifact Registry Reader
Why it's wrong here
Artifact Registry Reader (roles/artifactregistry.reader) is designed for pull or read-only operations—it includes permissions like artifactregistry.versions.list and artifactregistry.versions.get, which allow downloading artifacts, but it lacks all write permissions. A CI/CD pipeline that pushes images needs artifactregistry.versions.create and related write permissions, which the Reader role simply does not include. Using Reader would cause push requests to fail with permission denied errors, so it cannot fulfill the pipeline's requirement.
Go deeper
Related to this question
Learn chapter
Access Transparency and Access Approval
Key term
Artifact Registry
Artifact Registry is a managed service for storing, managing, and securing container images and other software packages in a centralized repository.
Key term
Service
A service is a software component or system that performs a specific function and is available to be used by other programs or users over a network.
About these practice questions
Courseiva writes every ACE question from scratch — 775 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.