Google PCA Manage and provision cloud infrastructure Practice Question
A developer needs to programmatically create and manage Compute Engine instances. Which Google Cloud service should they use to authenticate and authorize service accounts?
⚠ Common exam trap
Google Cloud often tests the misconception that Cloud Audit Logs or Cloud KMS can handle authentication/authorization, but candidates must remember that only Cloud IAM manages identities and permissions, while the other options serve logging or encryption purposes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud IAM
Cloud IAM is the correct service because it provides the identity and access management framework for authenticating and authorizing service accounts. When a developer creates Compute Engine instances, they must attach a service account and grant IAM roles (e.g., roles/compute.instanceAdmin) to define what actions that service account can perform. Cloud IAM handles the authentication via OAuth 2.0 tokens and authorization via role-based access control (RBAC), making it the foundational service for managing service account permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cloud Audit Logs
Why it's wrong here
Cloud Audit Logs records administrative and data-access activity for compliance and forensics; it cannot mint tokens or grant permissions. It appeals because audit trails frequently accompany service account work, yet the developer needs credentials and IAM role bindings to call Compute Engine APIs, which logging does not supply.
- ✗
Cloud Key Management Service (KMS)
Why it's wrong here
Cloud KMS manages encryption keys and performs cryptographic operations; it does not authenticate service accounts or authorise Compute Engine API calls. It tempts because KMS handles identity-adjacent secrets, but the developer requires IAM service accounts and their credentials, not key management, to create and manage instances.
- ✗
Cloud Scheduler
Why it's wrong here
Cloud Scheduler is a cron-style job runner that triggers workloads on a timetable; it neither issues nor validates service account credentials. It tempts because scheduled automation often calls Compute Engine APIs, but authentication and authorisation for those calls come from IAM service accounts, not the scheduler itself.
- ✓
Cloud IAM
Why this is correct
Cloud IAM provides the identity and access management layer for Google Cloud, letting code authenticate as a service account and receive scoped permissions to create and manage Compute Engine instances. It satisfies the stem's need for both authentication and authorisation of programmatic service account access.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Google Cloud Compute Options Overview
Key term
CAN
A CAN (Controller Area Network) is a robust vehicle bus standard designed to allow microcontrollers and devices to communicate with each other without a host computer.
Key term
Service account
A service account is a special type of account used by an application or a virtual machine, rather than a human user, to authenticate and interact with cloud services and APIs securely.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.