Courseiva
hardMultiple Choice

Google ACE Service Account Impersonation Practice Question

A Cloud Build pipeline needs to deploy to Cloud Run but the pipeline's service account has only minimal permissions. Rather than granting it Cloud Run Admin, the team wants it to temporarily act as a more privileged deployment service account. Which technique enables this?

⚠ Common exam trap

A common trap is confusing the Service Account User role (required for impersonation) with the Token Creator role (only for generating tokens). Candidates may also mistakenly think storing keys or using delegation is correct.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Grant service account impersonation: give the Cloud Build SA the Service Account User role on the deployment SA

Service account impersonation is the correct technique. The Cloud Build service account needs the Service Account User role (roles/iam.serviceAccountUser) on the deployment service account, which grants the iam.serviceAccounts.actAs permission to temporarily act as it. The Token Creator role only allows token generation, not usage. This approach avoids granting broad Cloud Run Admin permissions, adhering to least privilege. The other options are incorrect: A stores a static key (security risk), C grants excessive project-level Owner, and D is not a real IAM feature.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Download the deployment service account's JSON key and store it in Cloud Build secrets

    Why it's wrong here

    Storing a JSON key is not temporary and violates security best practices, as keys can be leaked; it is not the recommended impersonation technique.

  • ✓

    Grant service account impersonation: give the Cloud Build SA the Service Account User role on the deployment SA

    Why this is correct

    This is correct in concept, but the role should be Service Account User (roles/iam.serviceAccountUser), not Token Creator. The exam expects understanding that impersonation requires the actAs permission.

  • ✗

    Add the Cloud Build SA as an Owner of the project

    Why it's wrong here

    Granting the Cloud Build SA Owner role is excessive and violates least privilege; it would allow far more permissions than needed.

  • ✗

    Enable service account delegation in the project's IAM settings

    Why it's wrong here

    Service account delegation is not a standard IAM feature; the correct term is service account impersonation via the Service Account User role.

About these practice questions

This ACE question is part of Courseiva's 775-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.