Courseiva

Google PCA Design and plan a cloud solution architecture Practice Question

A financial analytics firm is deploying a new batch reporting platform on Google Cloud. The platform runs on a Managed Instance Group (MIG) of Compute Engine VMs and reads source data from a single Cloud Storage bucket. The security team requires that the VMs access the bucket without using long-lived service account keys, and that the identity be scoped specifically to this workload. They also want the permission to be automatically revoked when the VMs are deleted. Which approach should you recommend?

⚠ Common exam trap

The trap here is assuming that storing a service account key in Secret Manager makes it a short-lived or keyless credential.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a dedicated service account, grant it roles/storage.objectViewer on the bucket, and attach it to the MIG as the instance service account.

Workload-scoped, keyless authentication on Compute Engine is achieved by attaching a dedicated service account to the instance template used by the MIG. The metadata server issues short-lived tokens to the application, so no static keys exist to leak or rotate, and the identity disappears with the instances. Granting only roles/storage.objectViewer on the specific bucket enforces least privilege for the reporting workload.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the Compute Engine default service account, which already has the Editor role, and add an IAM condition limiting access to the reporting project.

    Why it's wrong here

    The default service account with Editor is broad and violates least privilege, giving the VMs far more access than reading one bucket. An IAM condition on the project does not narrow the permission to a single bucket or workload, and the default service account persists independently of the MIG, so access is not automatically revoked when the VMs are deleted.

  • ✓

    Create a dedicated service account, grant it roles/storage.objectViewer on the bucket, and attach it to the MIG as the instance service account.

    Why this is correct

    Attaching a dedicated service account to the MIG makes every VM in the group use that identity. Application Default Credentials on the VMs automatically obtain short-lived access tokens from the metadata server, so no keys are stored. Because the identity is tied to the instance template, deleting the VMs removes the workload's ability to authenticate, satisfying the revocation requirement.

  • ✗

    Enable Cloud Storage public access prevention and make the bucket readable by allAuthenticatedUsers, then restrict network access with VPC firewall rules.

    Why it's wrong here

    Granting allAuthenticatedUsers read access makes the bucket readable by every authenticated Google identity, not just this workload. Firewall rules control network reachability, not Cloud Storage IAM, and Cloud Storage is reached over Google's APIs rather than through VPC firewall rules. This fails the least-privilege and workload-scoped identity requirements.

  • ✗

    Create a service account, generate a JSON key, store it in Secret Manager, and have the application mount it at runtime.

    Why it's wrong here

    This creates a long-lived credential that must be rotated and can be exfiltrated if the secret is exposed. Secret Manager protects the key at rest, but the VM still holds a static private key, which directly violates the requirement to avoid long-lived service account keys. Revocation also depends on manual deletion of the key, not automatic removal with the VM.

About these practice questions

This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.