Courseiva

Google ACE Configuring Access and Security Practice Question

You need to allow a Compute Engine instance to securely access a Cloud Storage bucket without managing service account keys. The instance already has a service account attached. What is the best practice to grant access?

⚠ Common exam trap

The trap is thinking that you need to download a key file to authenticate, but the best practice is to use the attached service account. Candidates might also think that using the default service account is fine, but it's better to use a dedicated one with least privilege.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Grant the necessary IAM roles to the service account attached to the instance.

Granting the necessary IAM roles to the service account attached to the instance is the best practice because it allows the instance to authenticate to Cloud Storage using the service account's credentials automatically, without managing keys. This leverages the instance's metadata server to obtain access tokens, ensuring secure and seamless access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Download a service account key file and store it on the instance.

    Why it's wrong here

    Downloading a key file creates a long-lived credential that must be stored, rotated and protected, directly contradicting the no-key-management requirement. Keys are tempting for external workloads lacking an attached identity, but this instance already has a service account, so keyless authentication applies.

  • ✓

    Grant the necessary IAM roles to the service account attached to the instance.

    Why this is correct

    Attached service accounts supply credentials automatically through the metadata server, so granting the required IAM roles directly to that service account lets the instance access the bucket without any exported key files. This satisfies the no-key-management constraint.

  • ✗

    Create a new service account and use its key on the instance.

    Why it's wrong here

    A new service account with a key still requires key creation, distribution and rotation, failing the no-key-management requirement. Separate service accounts suit workloads needing distinct permissions, but the instance already has an attached identity, so a key adds risk without benefit.

  • ✗

    Use the default compute engine service account and grant it Storage Admin.

    Why it's wrong here

    While using the default compute engine service account with Storage Admin works, it grants more permissions than necessary (Storage Admin is broader). Best practice is to grant least privilege (e.g., Storage Object Viewer). Also, using a custom service account with specific roles is preferred over the default service account for better control.

About these practice questions

This ACE question is part of Courseiva's 775-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.