Google ACE Configuring Access and Security Practice Question
You need to allow a Compute Engine instance to securely access a Cloud Storage bucket without managing service account keys. The instance already has a service account attached. What is the best practice to grant access?
⚠ Common exam trap
The trap is thinking that you need to download a key file to authenticate, but the best practice is to use the attached service account. Candidates might also think that using the default service account is fine, but it's better to use a dedicated one with least privilege.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant the necessary IAM roles to the service account attached to the instance.
Granting the necessary IAM roles to the service account attached to the instance is the best practice because it allows the instance to authenticate to Cloud Storage using the service account's credentials automatically, without managing keys. This leverages the instance's metadata server to obtain access tokens, ensuring secure and seamless access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Download a service account key file and store it on the instance.
Why it's wrong here
Downloading a key file creates a long-lived credential that must be stored, rotated and protected, directly contradicting the no-key-management requirement. Keys are tempting for external workloads lacking an attached identity, but this instance already has a service account, so keyless authentication applies.
- ✓
Grant the necessary IAM roles to the service account attached to the instance.
Why this is correct
Attached service accounts supply credentials automatically through the metadata server, so granting the required IAM roles directly to that service account lets the instance access the bucket without any exported key files. This satisfies the no-key-management constraint.
- ✗
Create a new service account and use its key on the instance.
Why it's wrong here
A new service account with a key still requires key creation, distribution and rotation, failing the no-key-management requirement. Separate service accounts suit workloads needing distinct permissions, but the instance already has an attached identity, so a key adds risk without benefit.
- ✗
Use the default compute engine service account and grant it Storage Admin.
Why it's wrong here
While using the default compute engine service account with Storage Admin works, it grants more permissions than necessary (Storage Admin is broader). Best practice is to grant least privilege (e.g., Storage Object Viewer). Also, using a custom service account with specific roles is preferred over the default service account for better control.
Go deeper
Related to this question
Learn chapter
App Engine Security and IAP
Key term
Cloud storage
Cloud storage is a service that lets you save data on remote servers accessed over the internet instead of on your computer's hard drive.
Key term
Metadata server
A metadata server is a network-accessible service that provides configuration data, credentials, and instance-specific information to virtual machines running in a cloud environment like Google Cloud Platform.
About these practice questions
This ACE question is part of Courseiva's 775-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.