Courseiva
Designing for Security and CompliancemediumMultiple SelectObjective-mapped

Google PCA Designing for Security and Compliance Practice Question

A security team needs to restrict access to a set of Cloud Storage buckets so that only Compute Engine instances with a specific service account can read objects. Which TWO steps should they take? (Choose two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Grant the service account the 'roles/storage.objectViewer' role on the bucket

To restrict access to Cloud Storage buckets so that only Compute Engine instances with a specific service account can read objects, the correct approach is to use IAM permissions (option A) to grant the service account the 'roles/storage.objectViewer' role, and VPC Service Controls (option C) to create a perimeter that limits access to the VPC where the instances reside. IAM defines who can access resources, while VPC Service Controls enforce network-based boundaries. Firewall rules (option E) are not applicable to Cloud Storage access, as Cloud Storage is a global service accessed via HTTPS, not via IP ranges.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Grant the service account the 'roles/storage.objectViewer' role on the bucket

    Why this is correct

    This IAM role allows the service account to read objects.

  • Grant the user who owns the instances the 'roles/storage.admin' role

    Why it's wrong here

    This would grant bucket management to the user, not restrict access to the service account.

  • Configure VPC Service Controls to allow access only from the VPC where the instances reside

    Why this is correct

    VPC Service Controls can restrict access to Cloud Storage based on the source VPC, ensuring requests come from within the VPC.

  • Create a bucket ACL that allows read access for the service account

    Why it's wrong here

    ACLs are legacy; IAM is the preferred method.

  • Add a firewall rule allowing ingress from the service account to the bucket's IP range

    Why it's wrong here

    Firewall rules control network traffic to and from instances, not access to Cloud Storage (which is a managed service).

About these practice questions

This PCA question is part of Courseiva's 955-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.