Courseiva

Google PCA Identity-Aware Proxy (IAP) Practice Question

A security engineer wants to configure Identity-Aware Proxy (IAP) for an HTTPS load-balanced application to enforce zero-trust access. Users will authenticate with their Google accounts. What is the minimum set of IAM roles needed for a user to access the application behind IAP?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

roles/iap.httpsResourceAccessor

To access an application protected by IAP over HTTPS, a user must have the IAP-secured Web App User role (roles/iap.httpsResourceAccessor) on the resource. This role grants permission to access the resource through IAP. The other roles are not sufficient: roles/iam.serviceAccountUser is for managing service accounts, roles/iap.tunnelResourceAccessor is for TCP forwarding, and roles/compute.viewer only allows viewing Compute Engine resources, not accessing the application.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    roles/iam.serviceAccountUser

    Why it's wrong here

    serviceAccountUser lets a principal act as a service account, which is irrelevant to passing IAP's web-app authorisation check. It is tempting because it appears in many IAP deployment guides, but there it grants the load balancer's service account permission to act, not end-user access; the user needs roles/iap.httpsResourceAccessor.

  • ✗

    roles/iap.tunnelResourceAccessor

    Why it's wrong here

    tunnelResourceAccessor grants access to TCP tunnels through IAP for SSH or RDP to Compute Engine instances, not HTTP access to a load-balanced application. It is tempting because it is a genuine IAP role, but it applies to tunnelling scenarios; web access requires roles/iap.httpsResourceAccessor.

  • ✓

    roles/iap.httpsResourceAccessor

    Why this is correct

    roles/iap.httpsResourceAccessor grants a principal the ability to reach an IAP-protected HTTPS resource, satisfying the minimum-access requirement. It is the sole role needed for end users; roles/iap.admin and related roles govern configuration, not access, so they are unnecessary here.

  • ✗

    roles/compute.viewer

    Why it's wrong here

    compute.viewer only permits reading Compute Engine resource metadata; it carries no IAP authorisation, so the user is still blocked at the proxy. It is tempting because viewing the backend seems related to reaching it, but the required role is roles/iap.httpsResourceAccessor on the resource.

About these practice questions

This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.