mediumMultiple Choice
Google ACE Practice Question: Reviewing a GCP project's IAM policy and find…
You are reviewing a GCP project's IAM policy and find that the `allUsers` principal has `storage.objectViewer` on a Cloud Storage bucket. The bucket contains internal documentation. What are the security implications, and what should you do?
⚠ Common exam trap
The trap here is that candidates might think read-only permissions are safe or that UBLA automatically secures a bucket, but the Google Cloud ACE exam tests that `allUsers` with any IAM role (even read-only) on a bucket containing sensitive data is a critical security risk that must be removed immediately.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Any person on the internet can read the internal documents; remove the `allUsers` binding immediately and restrict access to authorized identities.
Granting `storage.objectViewer` to `allUsers` makes the bucket's objects publicly readable by anyone on the internet, including anonymous users. This violates the principle of least privilege and exposes internal documentation to unauthorized access. The immediate remediation is to remove the `allUsers` binding and replace it with specific, authenticated identities (e.g., service accounts or Google Groups) that require access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
This is acceptable if the bucket has Uniform Bucket-Level Access enabled; UBLA encrypts the data.
Why it's wrong here
UBLA governs object-level ACL uniformity, not public exposure; it does not encrypt data or restrict the allUsers principal. Granting storage.objectViewer to allUsers makes the internal documentation world-readable regardless of UBLA. UBLA is correctly chosen when enforcing consistent IAM-only access across a bucket's objects.
- ✓
Any person on the internet can read the internal documents; remove the `allUsers` binding immediately and restrict access to authorized identities.
Why this is correct
The allUsers principal grants access to anyone, authenticated or not, so storage.objectViewer lets the entire internet read the internal documentation. Removing that binding and granting access only to authorised identities eliminates the public exposure, satisfying the requirement to secure the bucket immediately.
- ✗
This is a read-only permission so it's acceptable — attackers can't modify the documents.
Why it's wrong here
Granting allUsers storage.objectViewer exposes internal documentation to anonymous internet reads, so confidentiality is breached regardless of write access. It is tempting because objectViewer genuinely cannot modify or delete objects, which would be acceptable only for a bucket intentionally published as a public static website.
- ✗
Enable Cloud Armor on the bucket to restrict access to your corporate IP range.
Why it's wrong here
Cloud Armor protects HTTP(S) load balancer traffic, not Cloud Storage bucket IAM, so it cannot restrict access to the objects. It is tempting for filtering requests by corporate IP range at the edge, which is correct for web applications behind a load balancer, not for bucket-level public exposure.
Go deeper
Related to this question
Learn chapter
GCP Security Services
Key term
Cloud storage
Cloud storage is a service that lets you save data on remote servers accessed over the internet instead of on your computer's hard drive.
Key term
IAM policy
An IAM policy is a set of rules that determines who can access specific cloud resources and what actions they are allowed to perform.
About these practice questions
This ACE question is part of Courseiva's 775-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.