Google PCA Manage implementation of cloud architecture Practice Question
A company runs a batch processing application on Compute Engine that reads data from Cloud Storage and writes results to BigQuery. The application runs on a managed instance group (MIG) with autoscaling. Recently, job failures occurred because instances could not authenticate to BigQuery. You need to ensure that the instances have the necessary permissions without embedding credentials in the application. What should you do?
⚠ Common exam trap
The trap here is thinking that you must use a service account key file for authentication, but Compute Engine instances can use their attached service account via the metadata server.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a service account with the BigQuery Data Editor role and assign it to the MIG as the instance service account.
Assigning a dedicated service account with the BigQuery Data Editor role to the managed instance group allows instances to obtain credentials from the metadata server, adhering to security best practices. This avoids key management and ensures least privilege. The other options either use insecure key files or grant excessive permissions to the default service account.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable the BigQuery API on the project and grant the Compute Engine default service account the BigQuery Data Editor role.
Why it's wrong here
The Compute Engine default service account has broad permissions by default, but granting it BigQuery Data Editor might violate least privilege. Moreover, if the default service account has been disabled or modified, this may not work. It is better to create a dedicated service account with only the necessary permissions and assign it to the MIG.
- ✗
Generate a service account key file and store it in Cloud Storage. Configure the application to download the key at startup and use it for authentication.
Why it's wrong here
Storing and using service account keys introduces security risks, such as key leakage and management overhead. Google recommends avoiding key files when possible. This approach also requires additional code to download and manage the key, and does not leverage the built-in metadata server authentication available to Compute Engine instances.
- ✓
Create a service account with the BigQuery Data Editor role and assign it to the MIG as the instance service account.
Why this is correct
Assigning a service account with the necessary BigQuery permissions to the MIG allows all instances to authenticate automatically via the metadata server. This eliminates the need to embed credentials and follows best practices for IAM. The BigQuery Data Editor role provides the required write access to datasets.
- ✗
Use Application Default Credentials (ADC) by setting the GOOGLE_APPLICATION_CREDENTIALS environment variable to point to a JSON key file stored on each instance's local SSD.
Why it's wrong here
This still relies on key files, which are difficult to rotate and secure. Storing keys on local SSD does not eliminate the risk of key compromise. ADC automatically uses the instance's service account if no key file is provided, so explicitly setting the environment variable to a key file is unnecessary and less secure.
Go deeper
Related to this question
Learn chapter
Google Cloud Compute Options Overview
Key term
Managed instance group
A managed instance group is a collection of identical virtual machine instances that are automatically managed as a single unit to ensure high availability and scalability.
Key term
Instance group
An instance group is a collection of virtual machine instances that are managed as a single unit for scaling, load balancing, and lifecycle management in cloud computing.
About these practice questions
Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.