Google PCA Design and plan a cloud solution architecture Practice Question
A company wants to restrict access to a Cloud Storage bucket so that only a specific service account can read objects. The bucket contains sensitive data. Which identity and access management (IAM) approach should the architect use?
⚠ Common exam trap
Google Cloud often tests the misconception that granting a broad role like roles/storage.admin is acceptable for simplicity, but the trap here is that candidates overlook the principle of least privilege and the specific read-only requirement, leading them to choose an overly permissive role.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant the service account roles/storage.objectViewer on the bucket and remove all other bindings.
The principle of least privilege dictates that the service account should be granted only the minimal permissions required to read objects, which is roles/storage.objectViewer. By removing all other bindings, the bucket becomes accessible exclusively to that service account, ensuring that no other identities (users, groups, or other service accounts) can read the sensitive data. This approach directly enforces the requirement using IAM roles on the bucket resource.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Grant the service account roles/iam.serviceAccountUser on the bucket.
Why it's wrong here
roles/iam.serviceAccountUser lets a principal act as a service account, for example attaching it to a resource; it grants no permission to read objects in Cloud Storage. It tempts because the role name mentions service accounts, and it would be correct when a user must deploy workloads that impersonate that service account.
- ✗
Use a signed URL to allow access for the service account.
Why it's wrong here
A signed URL grants time-limited access to anyone holding the link, not to a specific service account, so it cannot restrict reads to that identity. It tempts for sharing single objects securely without changing IAM, which would be correct for temporary external access to one object rather than persistent identity-scoped bucket permissions.
- ✗
Grant the service account roles/storage.admin on the bucket.
Why it's wrong here
roles/storage.admin grants full control over buckets and objects, including delete and IAM changes, far exceeding the read-only requirement and violating least privilege for sensitive data. It tempts because it certainly permits reading, and it would be correct for an administrator managing bucket configuration and permissions.
- ✓
Grant the service account roles/storage.objectViewer on the bucket and remove all other bindings.
Why this is correct
Granting `roles/storage.objectViewer` at bucket level binds the service account directly to the resource, satisfying the least-privilege constraint. Removing every other binding ensures no principal inherits access via project-level or inherited roles, so only that service account can read objects. This is the precise mechanism for restricting a sensitive bucket to a single identity.
Go deeper
Related to this question
Learn chapter
Data Migration and Transfer Services
Key term
Service account
A service account is a special type of account used by an application or a virtual machine, rather than a human user, to authenticate and interact with cloud services and APIs securely.
Key term
Data
Data is raw, unprocessed information, like numbers, words, or measurements, that can be stored, processed, and analyzed by computers.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.