Google PCA IAM Conditions Practice Question
A company wants to restrict access to a Cloud Storage bucket so that only objects encrypted with a specific Cloud KMS key can be read. Which approach should they use?
⚠ Common exam trap
The trap is that candidates may think a bucket policy can enforce encryption-key-based access using a condition like `request.object.encryption.type`, but Cloud Storage IAM conditions do not support that attribute. The correct mechanism is Key Access Justifications on the Cloud KMS key.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Key Access Justifications on the Cloud KMS key and allow access only for justified requests.
To restrict access to a Cloud Storage bucket so that only objects encrypted with a specific Cloud KMS key can be read, the company should enable Key Access Justifications (KAJ) on the Cloud KMS key and allow access only for justified requests. KAJ provides the ability to enforce access policies based on the justification provided for a key operation, effectively tying object access to the specific key. Option B is incorrect because Cloud Storage bucket policies do not support conditions on `request.object.encryption.type`; that attribute is not a valid IAM condition for Cloud Storage. Option C is incorrect because `resource.hasTag` is not a valid IAM condition attribute for Cloud Storage objects. Option D is incorrect because VPC Service Controls provide perimeter-based security but do not restrict access based on the encryption key of individual objects.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable Key Access Justifications on the Cloud KMS key and allow access only for justified requests.
Why this is correct
Incorrect. Key Access Justifications provide logging and justification for key usage but do not control read access to objects based on encryption key.
- ✗
Set a bucket policy that denies access if the object's encryption type is not CMEK.
Why it's wrong here
Correct. By denying access if the encryption type is not CMEK, you ensure only objects encrypted with a Cloud KMS key can be read. This can be combined with a condition on the specific key resource name for more granular control.
- ✗
Use IAM conditions with the resource name condition 'resource.name.startsWith("projects/_/buckets/example-bucket/objects/")' and 'resource.hasTag("kmsKeyName", "projects/p/locations/l/keyRings/kr/cryptoKeys/ck")'.
Why it's wrong here
Incorrect. The `resource.hasTag` attribute is not valid for Cloud Storage object IAM conditions. The correct attribute for encryption key is `request.object.encryption.key_name`.
- ✗
Configure VPC Service Controls to include the bucket and the Cloud KMS key resource.
Why it's wrong here
Incorrect. VPC Service Controls restrict data exfiltration across perimeters but do not enforce per-object encryption key requirements for read access.
Go deeper
Related to this question
Learn chapter
Resource Monitoring and Logging with Cloud Operations
Key term
VPC Service Controls
VPC Service Controls is a Google Cloud security feature that protects the data of managed services by defining perimeters that prevent data exfiltration and unauthorized access across public networks.
Key term
KMS
KMS (Key Management Service) is a Microsoft technology that automates volume licensing activation for Windows and Office products within an organization's network.
About these practice questions
Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.