Courseiva
mediumMultiple Choice

Google ACE Practice Question: A DevOps engineer creates a service account for a…

A DevOps engineer creates a service account for a CI/CD pipeline. The pipeline needs to push container images to Artifact Registry. Which role grants the minimum required permission?

⚠ Common exam trap

Google Cloud often tests the misconception that Artifact Registry is just a wrapper around Cloud Storage, leading candidates to choose Storage Object Creator, but in reality, Artifact Registry uses its own IAM roles and does not expose the underlying bucket for direct permission assignment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Artifact Registry Writer

The Artifact Registry Writer role provides the minimal permissions needed to push container images to Artifact Registry, specifically the `artifactregistry.writer` permission. This role allows writing artifacts without granting broader administrative or read-only access, aligning with the principle of least privilege.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Artifact Registry Administrator

    Why it's wrong here

    Artifact Registry Administrator (roles/artifactregistry.admin) grants the full set of Artifact Registry permissions, including creation and deletion of repositories, editing repository settings, and managing IAM policies. For a CI/CD pipeline whose only job is to push artifacts to a pre-existing repository, this is far too broad and violates least privilege. An attacker or compromised build job with this role could delete repositories or grant themselves additional access, making the Writer role the safer choice.

  • ✓

    Artifact Registry Writer

    Why this is correct

    Artifact Registry Writer (roles/artifactregistry.writer) is the correct predefined role for a CI/CD pipeline that needs to push container images or packages. It grants exactly the permissions required to upload artifacts—e.g., artifactregistry.versions.create, artifactregistry.files.create, and artifactregistry.tags.create—without allowing destructive actions like deleting repositories or altering IAM policies. This aligns with least privilege because the pipeline only needs write access on an existing repository, not administrative control.

  • ✗

    Storage Object Creator on the underlying Cloud Storage bucket

    Why it's wrong here

    Storage Object Creator on the underlying Cloud Storage bucket is ineffective because Artifact Registry is a separate managed service with its own IAM permission model; it is not a direct wrapper around a user-visible GCS bucket. Even if artifact data is physically stored in Google-managed storage, the bucket is not accessible or modifiable by customers, and bucket-level IAM does not grant Artifact Registry API permissions such as artifactregistry.versions.create. A CI/CD pipeline pushing to Artifact Registry must have an Artifact Registry role, not a Cloud Storage role.

  • ✗

    Artifact Registry Reader

    Why it's wrong here

    Artifact Registry Reader (roles/artifactregistry.reader) is designed for pull or read-only operations—it includes permissions like artifactregistry.versions.list and artifactregistry.versions.get, which allow downloading artifacts, but it lacks all write permissions. A CI/CD pipeline that pushes images needs artifactregistry.versions.create and related write permissions, which the Reader role simply does not include. Using Reader would cause push requests to fail with permission denied errors, so it cannot fulfill the pipeline's requirement.

About these practice questions

Courseiva writes every ACE question from scratch — 775 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.