Courseiva

Generative AI Leader Fundamentals of Generative AI Practice Question

Exhibit

Error: 403 Permission 'aiplatform.endpoints.predict' denied on resource 'projects/my-project/locations/us-central1/endpoints/my-endpoint'.

Refer to the exhibit. A developer sees this error when trying to call a Vertex AI endpoint for online prediction. What permission does the requesting identity need to be granted?

⚠ Common exam trap

Google Cloud often tests the distinction between permissions scoped to endpoints versus models, and candidates mistakenly choose `aiplatform.models.predict` because they think prediction is always tied to the model, not the endpoint serving it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

aiplatform.endpoints.predict

The error occurs when calling a Vertex AI endpoint for online prediction, which requires the `aiplatform.endpoints.predict` permission. This permission is specifically scoped to the endpoint resource, allowing the identity to send prediction requests to a deployed model endpoint. The correct IAM role binding must include this permission for the requesting identity to successfully invoke the endpoint.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    aiplatform.prediction.predict

    Why it's wrong here

    aiplatform.prediction.predict is not a grantable IAM permission; prediction access is controlled through roles containing aiplatform.endpoints.predict. It tempts because the name mirrors the predict action, but IAM permissions must match those defined by the Vertex AI service, not descriptive guesses.

  • ✓

    aiplatform.endpoints.predict

    Why this is correct

    Granting `aiplatform.endpoints.predict` satisfies the online prediction constraint: it authorises the requesting identity to send prediction requests to a Vertex AI endpoint. This permission is contained in roles such as Vertex AI User, and is the minimum required for calling `predict` on a deployed endpoint.

  • ✗

    aiplatform.endpoints.use

    Why it's wrong here

    aiplatform.endpoints.use does not exist in Vertex AI's IAM permission set; invoking an endpoint for online prediction requires aiplatform.endpoints.predict. It tempts because endpoint management roles sound related, but managing an endpoint is distinct from sending prediction requests to it.

  • ✗

    aiplatform.models.predict

    Why it's wrong here

    aiplatform.models.predict is not a valid IAM permission; online prediction against a deployed endpoint is authorised by aiplatform.endpoints.predict. It tempts because predictions conceptually involve a model, but the endpoint resource, not the model resource, governs the permission.

About these practice questions

Courseiva writes every Generative AI Leader question from scratch — 1,008 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This Generative AI Leader practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Generative AI Leader exam.