Courseiva

Google PCA IAM Conditions Practice Question

A company wants to restrict access to a Cloud Storage bucket so that only objects encrypted with a specific Cloud KMS key can be read. Which approach should they use?

⚠ Common exam trap

The trap is that candidates may think a bucket policy can enforce encryption-key-based access using a condition like `request.object.encryption.type`, but Cloud Storage IAM conditions do not support that attribute. The correct mechanism is Key Access Justifications on the Cloud KMS key.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Key Access Justifications on the Cloud KMS key and allow access only for justified requests.

To restrict access to a Cloud Storage bucket so that only objects encrypted with a specific Cloud KMS key can be read, the company should enable Key Access Justifications (KAJ) on the Cloud KMS key and allow access only for justified requests. KAJ provides the ability to enforce access policies based on the justification provided for a key operation, effectively tying object access to the specific key. Option B is incorrect because Cloud Storage bucket policies do not support conditions on `request.object.encryption.type`; that attribute is not a valid IAM condition for Cloud Storage. Option C is incorrect because `resource.hasTag` is not a valid IAM condition attribute for Cloud Storage objects. Option D is incorrect because VPC Service Controls provide perimeter-based security but do not restrict access based on the encryption key of individual objects.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable Key Access Justifications on the Cloud KMS key and allow access only for justified requests.

    Why this is correct

    Incorrect. Key Access Justifications provide logging and justification for key usage but do not control read access to objects based on encryption key.

  • ✗

    Set a bucket policy that denies access if the object's encryption type is not CMEK.

    Why it's wrong here

    Correct. By denying access if the encryption type is not CMEK, you ensure only objects encrypted with a Cloud KMS key can be read. This can be combined with a condition on the specific key resource name for more granular control.

  • ✗

    Use IAM conditions with the resource name condition 'resource.name.startsWith("projects/_/buckets/example-bucket/objects/")' and 'resource.hasTag("kmsKeyName", "projects/p/locations/l/keyRings/kr/cryptoKeys/ck")'.

    Why it's wrong here

    Incorrect. The `resource.hasTag` attribute is not valid for Cloud Storage object IAM conditions. The correct attribute for encryption key is `request.object.encryption.key_name`.

  • ✗

    Configure VPC Service Controls to include the bucket and the Cloud KMS key resource.

    Why it's wrong here

    Incorrect. VPC Service Controls restrict data exfiltration across perimeters but do not enforce per-object encryption key requirements for read access.

Go deeper

Related to this question

About these practice questions

Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.