Google ACE Configuring Access and Security Practice Question
An organization has a requirement that all Compute Engine instances must be able to access only a specific set of Google Cloud APIs, and no others. The security team wants to enforce this using IAM and access scopes. Which combination should they use?
⚠ Common exam trap
The trap here is thinking that IAM roles alone control API access, or that broad scopes like cloud-platform are necessary for functionality.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the instance's access scopes to the specific APIs needed and grant the service account only the necessary IAM roles.
Access scopes and IAM roles together control what APIs an instance can access. Scopes set the maximum allowed APIs, while IAM roles grant specific permissions. To restrict an instance to a specific set of APIs, set the scopes to only those APIs and grant the service account only the IAM roles needed for those APIs. This layered approach ensures least privilege and meets the security requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Set the instance's access scopes to the specific APIs needed and grant the service account only the necessary IAM roles.
Why this is correct
Access scopes define the maximum set of APIs an instance can call, while IAM roles determine the actual permissions. By setting scopes to only the required APIs and granting minimal IAM roles, the instance is restricted to exactly the needed APIs. This enforces defense in depth and meets the requirement of limiting access to a specific set.
- ✗
Disable all access scopes and rely solely on IAM roles to control API access.
Why it's wrong here
Disabling all access scopes would prevent the instance from accessing any Google Cloud APIs, even if IAM roles are granted. Access scopes and IAM roles work together; scopes act as a ceiling. You cannot rely solely on IAM roles if scopes are disabled. This option would break functionality and not meet the requirement of allowing a specific set of APIs.
- ✗
Set the instance's access scopes to cloud-platform and grant the service account the Editor role.
Why it's wrong here
Setting the cloud-platform scope allows access to all Google Cloud APIs, which is the opposite of restricting to a specific set. Granting the Editor role also provides broad permissions across many services. This combination does not enforce the requirement of limiting access to only a specific set of APIs and violates least privilege.
- ✗
Use the default access scopes and grant the service account the Viewer role.
Why it's wrong here
Default access scopes typically allow broad read access to many APIs, which does not restrict the instance to a specific set. The Viewer role also grants read access to a wide range of resources across services. This combination fails to limit the instance to only the required APIs and does not satisfy the security team's requirement.
Go deeper
Related to this question
Learn chapter
Security Command Center Premium Findings
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
Key term
Service account
A service account is a special type of account used by an application or a virtual machine, rather than a human user, to authenticate and interact with cloud services and APIs securely.
About these practice questions
One of 775 original ACE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.