Courseiva

Google PCA Manage and provision cloud infrastructure Practice Question

A developer needs to programmatically create and manage Compute Engine instances. Which Google Cloud service should they use to authenticate and authorize service accounts?

⚠ Common exam trap

Google Cloud often tests the misconception that Cloud Audit Logs or Cloud KMS can handle authentication/authorization, but candidates must remember that only Cloud IAM manages identities and permissions, while the other options serve logging or encryption purposes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cloud IAM

Cloud IAM is the correct service because it provides the identity and access management framework for authenticating and authorizing service accounts. When a developer creates Compute Engine instances, they must attach a service account and grant IAM roles (e.g., roles/compute.instanceAdmin) to define what actions that service account can perform. Cloud IAM handles the authentication via OAuth 2.0 tokens and authorization via role-based access control (RBAC), making it the foundational service for managing service account permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cloud Audit Logs

    Why it's wrong here

    Cloud Audit Logs records administrative and data-access activity for compliance and forensics; it cannot mint tokens or grant permissions. It appeals because audit trails frequently accompany service account work, yet the developer needs credentials and IAM role bindings to call Compute Engine APIs, which logging does not supply.

  • ✗

    Cloud Key Management Service (KMS)

    Why it's wrong here

    Cloud KMS manages encryption keys and performs cryptographic operations; it does not authenticate service accounts or authorise Compute Engine API calls. It tempts because KMS handles identity-adjacent secrets, but the developer requires IAM service accounts and their credentials, not key management, to create and manage instances.

  • ✗

    Cloud Scheduler

    Why it's wrong here

    Cloud Scheduler is a cron-style job runner that triggers workloads on a timetable; it neither issues nor validates service account credentials. It tempts because scheduled automation often calls Compute Engine APIs, but authentication and authorisation for those calls come from IAM service accounts, not the scheduler itself.

  • ✓

    Cloud IAM

    Why this is correct

    Cloud IAM provides the identity and access management layer for Google Cloud, letting code authenticate as a service account and receive scoped permissions to create and manage Compute Engine instances. It satisfies the stem's need for both authentication and authorisation of programmatic service account access.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.