Courseiva
Setting Up a Cloud Solution EnvironmenteasyMultiple ChoiceObjective-mapped

Google ACE Setting Up a Cloud Solution Environment Practice Question

What is the basic role that grants full control over all resources in a GCP project?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Owner

The Owner role (roles/owner) grants full access, including the ability to manage roles and billing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Editor

    Why it's wrong here

    The Editor basic role grants permissions to create, modify, and delete resources, but it deliberately excludes IAM policy management and billing access. The Editor role cannot grant roles to other principals, cannot set IAM policies at any level, and cannot view or alter billing information, so it falls short of full control. For example, an Editor on a project can deploy Compute Engine instances or update Cloud Storage objects, but cannot add an Owner or change project-level IAM bindings.

  • Owner

    Why this is correct

    The Owner basic role is the highest-level predefined role in Cloud IAM, encompassing all Editor permissions plus the ability to manage IAM policies, set billing accounts, and configure organization-level settings when applied at the project or organization level. An Owner can grant any role to any principal, including making another user an Owner, and can view or change the project's billing account and payment details. This role is typically reserved for a small number of administrators because it provides unrestricted management of the project and its entire resource hierarchy.

  • Viewer

    Why it's wrong here

    The Viewer basic role is strictly read-only, granting permissions to view (but not modify) existing resources, and it does not include any ability to perform actions such as starting instances, writing data, or changing configurations. A Viewer cannot delete resources, cannot modify IAM policies, and cannot access billing information. This role is suitable for auditing or reporting purposes but is insufficient for any administrative or operational task.

  • Admin

    Why it's wrong here

    There is no predefined basic role named 'Admin' in Google Cloud IAM. IAM offers three basic roles (Viewer, Editor, Owner) plus a set of predefined roles like roles/admin or roles/resourcemanager.projectIamAdmin, but 'Admin' by itself is not a valid basic role. If a user has a custom role with 'Admin' in its name, that role's permissions are not granted globally; it must be explicitly bound to a resource. Therefore, selecting 'Admin' as a basic role that grants full control is incorrect because the role does not exist in that category.

About these practice questions

One of 769 original ACE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.