Courseiva

Cloud Digital Leader Why cloud technology is transforming business Practice Question

Exhibit

Refer to the exhibit. The following IAM policy is attached to a Cloud Storage bucket:
{
  "bindings": [
    {
      "role": "roles/storage.objectViewer",
      "members": ["user:alice@example.com"]
    },
    {
      "role": "roles/storage.objectCreator",
      "members": ["group:devs@example.com"]
    }
  ]
}

Alice has been granted the Storage Object Viewer (roles/storage.objectViewer) IAM role on a Cloud Storage bucket. What access does Alice have to the bucket?

⚠ Common exam trap

Google Cloud often tests the misconception that 'read-only' access implies the ability to list bucket contents but not download objects, whereas in Cloud Storage, read access includes both listing and downloading objects via the storage.objects.get permission.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Read objects only

The Storage Object Viewer role grants permissions to list and read objects in a bucket, which means Alice can read objects only. It does not grant permission to write objects or manage the bucket.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Write objects only

    Why it's wrong here

    Write objects only would require the roles/storage.objectCreator role, which grants the storage.objects.create permission. Alice is not assigned this role, nor does she have any other role that includes write access. Without objectCreator or objectAdmin, she cannot upload or overwrite objects, so this option is incorrect.

  • ✗

    Full control

    Why it's wrong here

    Full control corresponds to roles/storage.objectAdmin, which includes storage.objects.get, list, create, delete, and update, as well as storage.objects.setIamPolicy and getIamPolicy for object-level permissions. Alice only has read access, so she lacks the administrative and deletion permissions needed for full control. This option would require a much broader set of IAM bindings than what Alice actually has.

  • ✓

    Read objects only

    Why this is correct

    The correct access is read-only, granted by the roles/storage.objectViewer role. This predefined role includes storage.objects.get and storage.objects.list, enabling Alice to list the bucket's objects and download or view their contents. Because objectViewer does not include any storage.objects.create or storage.objects.delete permissions, Alice can only read, not modify, the data.

  • ✗

    Read and write objects

    Why it's wrong here

    Read and write access would require Alice to hold both a read permission set and a write permission set, such as objectViewer and objectCreator or a single objectAdmin role. While she does have objectViewer, she lacks any write-granting role like objectCreator or objectAdmin. Without the storage.objects.create permission, the write half of this option is unsupported, making it incorrect.

About these practice questions

One of 848 original GCDL practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.