Courseiva
easyMultiple Choice

Cloud Digital Leader Practice Question: Refer to the exhibit

Exhibit

Refer to the exhibit.
```
Error: 403 POST https://storage.googleapis.com/storage/v1/b/bucket/o:copyTo?sourceObject=source.txt
<Code>AccessDenied</Code>
<Message>Access denied.</Message>
```

Refer to the exhibit. A user receives this error when trying to copy an object from one bucket to another. What is the most likely cause?

⚠ Common exam trap

Google Cloud often tests the misconception that cross-region copy is blocked by default, but in Google Cloud Storage, cross-region copies are allowed as long as IAM permissions are correct, making permissions the primary gatekeeper.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The service account used does not have the required IAM permissions to copy objects.

The error when copying an object between buckets is most likely due to insufficient IAM permissions. In Google Cloud, the service account initiating the copy must have both `storage.objects.get` (to read the source object) and `storage.objects.create` (to write to the destination bucket) permissions. Without these, the operation fails with an access denied error, even if the buckets exist and are accessible.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The service account used does not have the required IAM permissions to copy objects.

    Why this is correct

    A 403 Forbidden error in Google Cloud Storage means the request was authenticated but not authorized. To copy an object, the service account must have both storage.objects.get on the source bucket (or object) and storage.objects.create on the destination bucket—roles such as roles/storage.objectViewer plus roles/storage.objectCreator, or the combined roles/storage.objectAdmin, provide these permissions. If the service account lacks them, the copy operation fails with AccessDenied regardless of whether the buckets and objects exist and are reachable. Also verify that no organization policy or IAM deny rule is blocking the specific access.

  • ✗

    The buckets are located in different regions and cross-region copy is not allowed.

    Why it's wrong here

    Google Cloud Storage fully supports copying objects between buckets in different regions; the copy operation reads from the source and writes to the destination, and GCS handles the transfer internally. There is no built-in prohibition against cross-region copy that would generate a 403 Forbidden. If a policy were blocking cross-region access—for example, a VPC Service Controls perimeter with restricted egress—the error would include a specific policy-related reason and would not be described simply as 'regions are different'. Thus a 403 here cannot be attributed to differing bucket locations.

  • ✗

    The destination bucket has exceeded its storage quota.

    Why it's wrong here

    A destination bucket exceeding its storage quota does not produce a 403 Forbidden; Google Cloud Storage returns a 429 Too Many Requests error with a quotaExceeded reason when a project's total bucket storage usage exceeds its default limit (often 5 TiB). Quota violations are distinct from authorization failures: the caller is authenticated and permitted, but the request is rejected because a usage limit is reached. Additionally, individual buckets do not have a hard-coded capacity quota by default—only project-level quotas apply—so 'destination bucket quota exceeded' is not a plausible cause of a 403.

  • ✗

    The source bucket name is misspelled in the request.

    Why it's wrong here

    A misspelled source bucket name would yield a 404 Not Found, not a 403 Forbidden, because the service would fail to resolve the bucket URL to an existing resource. The copy operation first looks up the source bucket; if the bucket name is incorrect or the bucket exists under a different project and is inaccessible, the API returns 404 or 403 depending on whether the name is nonexistent or just lacking permissions. However, a 403 with a valid bucket name indicates the identity was recognized but lacks the specific IAM permissions for the copy action—the request was processed far enough to determine authorization, which would not happen for a nonexistent bucket.

About these practice questions

This GCDL question is part of Courseiva's 848-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.