Courseiva

Google PCA Design and plan a cloud solution architecture Practice Question

A company wants to restrict access to a Cloud Storage bucket so that only a specific service account can read objects. The bucket contains sensitive data. Which identity and access management (IAM) approach should the architect use?

⚠ Common exam trap

Google Cloud often tests the misconception that granting a broad role like roles/storage.admin is acceptable for simplicity, but the trap here is that candidates overlook the principle of least privilege and the specific read-only requirement, leading them to choose an overly permissive role.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Grant the service account roles/storage.objectViewer on the bucket and remove all other bindings.

The principle of least privilege dictates that the service account should be granted only the minimal permissions required to read objects, which is roles/storage.objectViewer. By removing all other bindings, the bucket becomes accessible exclusively to that service account, ensuring that no other identities (users, groups, or other service accounts) can read the sensitive data. This approach directly enforces the requirement using IAM roles on the bucket resource.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Grant the service account roles/iam.serviceAccountUser on the bucket.

    Why it's wrong here

    roles/iam.serviceAccountUser lets a principal act as a service account, for example attaching it to a resource; it grants no permission to read objects in Cloud Storage. It tempts because the role name mentions service accounts, and it would be correct when a user must deploy workloads that impersonate that service account.

  • ✗

    Use a signed URL to allow access for the service account.

    Why it's wrong here

    A signed URL grants time-limited access to anyone holding the link, not to a specific service account, so it cannot restrict reads to that identity. It tempts for sharing single objects securely without changing IAM, which would be correct for temporary external access to one object rather than persistent identity-scoped bucket permissions.

  • ✗

    Grant the service account roles/storage.admin on the bucket.

    Why it's wrong here

    roles/storage.admin grants full control over buckets and objects, including delete and IAM changes, far exceeding the read-only requirement and violating least privilege for sensitive data. It tempts because it certainly permits reading, and it would be correct for an administrator managing bucket configuration and permissions.

  • ✓

    Grant the service account roles/storage.objectViewer on the bucket and remove all other bindings.

    Why this is correct

    Granting `roles/storage.objectViewer` at bucket level binds the service account directly to the resource, satisfying the least-privilege constraint. Removing every other binding ensures no principal inherits access via project-level or inherited roles, so only that service account can read objects. This is the precise mechanism for restricting a sensitive bucket to a single identity.

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.