Courseiva

Google PCA Manage implementation of cloud architecture Practice Question

A company runs a batch processing application on Compute Engine that reads data from Cloud Storage and writes results to BigQuery. The application runs on a managed instance group (MIG) with autoscaling. Recently, job failures occurred because instances could not authenticate to BigQuery. You need to ensure that the instances have the necessary permissions without embedding credentials in the application. What should you do?

⚠ Common exam trap

The trap here is thinking that you must use a service account key file for authentication, but Compute Engine instances can use their attached service account via the metadata server.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a service account with the BigQuery Data Editor role and assign it to the MIG as the instance service account.

Assigning a dedicated service account with the BigQuery Data Editor role to the managed instance group allows instances to obtain credentials from the metadata server, adhering to security best practices. This avoids key management and ensures least privilege. The other options either use insecure key files or grant excessive permissions to the default service account.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable the BigQuery API on the project and grant the Compute Engine default service account the BigQuery Data Editor role.

    Why it's wrong here

    The Compute Engine default service account has broad permissions by default, but granting it BigQuery Data Editor might violate least privilege. Moreover, if the default service account has been disabled or modified, this may not work. It is better to create a dedicated service account with only the necessary permissions and assign it to the MIG.

  • ✗

    Generate a service account key file and store it in Cloud Storage. Configure the application to download the key at startup and use it for authentication.

    Why it's wrong here

    Storing and using service account keys introduces security risks, such as key leakage and management overhead. Google recommends avoiding key files when possible. This approach also requires additional code to download and manage the key, and does not leverage the built-in metadata server authentication available to Compute Engine instances.

  • ✓

    Create a service account with the BigQuery Data Editor role and assign it to the MIG as the instance service account.

    Why this is correct

    Assigning a service account with the necessary BigQuery permissions to the MIG allows all instances to authenticate automatically via the metadata server. This eliminates the need to embed credentials and follows best practices for IAM. The BigQuery Data Editor role provides the required write access to datasets.

  • ✗

    Use Application Default Credentials (ADC) by setting the GOOGLE_APPLICATION_CREDENTIALS environment variable to point to a JSON key file stored on each instance's local SSD.

    Why it's wrong here

    This still relies on key files, which are difficult to rotate and secure. Storing keys on local SSD does not eliminate the risk of key compromise. ADC automatically uses the instance's service account if no key file is provided, so explicitly setting the environment variable to a key file is unnecessary and less secure.

About these practice questions

Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.