Courseiva

Generative AI Leader Google Cloud's Generative AI Offerings Practice Question

Exhibit

{
  "bindings": [
    {
      "role": "roles/aiplatform.admin",
      "members": ["user:alice@example.com"]
    }
  ]
}

Refer to the exhibit. This is the IAM policy for a project containing a Vertex AI Agent Builder agent and a data store. The agent is unable to access the data store. What is the most likely cause?

⚠ Common exam trap

A common trap in Google Cloud IAM is confusing user permissions with service account permissions. The agent uses a service account, not the user's credentials, so the data store viewer role must be granted to the service account.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The agent service account needs the data store viewer role

The agent service account must have the Data Store Viewer role (or equivalent permissions) to read data from the data store. Without this role, the agent cannot access the indexed content, even if the user has permissions. This is a common IAM misconfiguration in Vertex AI Agent Builder.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The user needs more permissions

    Why it's wrong here

    The agent accesses the data store through its own service account, so end-user permissions are irrelevant to that call. Granting the user more roles is right when a human is directly denied access to a resource they must query.

  • ✗

    The agent needs a bigger quota

    Why it's wrong here

    Quotas govern request rates and resource consumption, not identity-based authorisation, so they cannot block access when the IAM policy itself omits the required permission binding. Quotas become the answer when a service returns rate-limit or resource-exhausted errors despite valid credentials and correctly scoped IAM roles.

  • ✓

    The agent service account needs the data store viewer role

    Why this is correct

    The agent's service account lacks the data store viewer role, so its retrieval calls are denied. Granting that role on the data store satisfies the stem's access requirement, since the agent must read the store to ground responses.

  • ✗

    The data store is not in the same region

    Why it's wrong here

    Region mismatch produces deployment or discovery errors, not an access denial; cross-region data stores remain reachable when IAM grants allow it. Region selection matters for latency and data residency, so it is a plausible-sounding but unrelated cause here.

About these practice questions

Courseiva writes every Generative AI Leader question from scratch — 1,008 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This Generative AI Leader practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Generative AI Leader exam.