Courseiva

Google PCA Manage and provision cloud infrastructure Practice Question

A service account needs to be able to start and stop Compute Engine instances in a specific project. Which IAM role should be assigned at the project level?

⚠ Common exam trap

Google Cloud often tests the distinction between primitive roles (like roles/editor) and predefined roles (like roles/compute.instanceAdmin.v1), where candidates mistakenly choose the broader role due to its apparent convenience, overlooking the principle of least privilege and the specific permissions required for the task.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

roles/compute.instanceAdmin.v1

Roles/compute.instanceAdmin.v1, because this role grants the necessary permissions to start, stop, and manage Compute Engine instances, including operations like instances.start and instances.stop, at the project level. This role is specifically designed for managing compute resources without granting broader project-level access like editing all resources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    roles/iam.serviceAccountUser

    Why it's wrong here

    roles/iam.serviceAccountUser lets a principal act as a service account, for example attaching one to a VM, but grants no permission to start or stop Compute Engine instances. It is tempting because the name suggests account-level control, and it would be correct when a user must deploy resources that run under a specific service account's identity.

  • ✗

    roles/editor

    Why it's wrong here

    roles/editor bundles broad create, update, and delete permissions across many services, violating least privilege for a task needing only start and stop. It is tempting because it certainly permits those operations, and it would be correct for a service account genuinely requiring wide write access across multiple GCP services rather than two Compute Engine methods.

  • ✗

    roles/compute.viewer

    Why it's wrong here

    roles/compute.viewer grants only read access to Compute Engine resources, so it cannot perform the instances.start or instances.stop operations the service account requires. It is tempting because viewing instances is often paired with managing them, and it would be correct for a monitoring or auditing service account that only needs to list and inspect VM state.

  • ✓

    roles/compute.instanceAdmin.v1

    Why this is correct

    roles/compute.instanceAdmin.v1 grants permissions to start, stop, reset and manage Compute Engine instances, including instance-level operations, at the project scope. That matches the requirement precisely, unlike narrower roles such as compute.viewer or instance-specific permissions that omit start and stop.

About these practice questions

This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.