Courseiva

Google PCA Manage implementation of cloud architecture Practice Question

A startup is setting up a CI/CD pipeline for their web application using Cloud Build and Cloud Deploy. They have configured a Cloud Build trigger that executes on pushes to the main branch of a Cloud Source Repositories repository. The trigger runs a build step that builds a Docker image and pushes it to Artifact Registry, then creates a release using Cloud Deploy. The pipeline fails with an error message indicating that the Cloud Build service account does not have permission to create releases. What should the architect do to resolve the issue?

⚠ Common exam trap

The trap here is that candidates might assume the Cloud Build service account has sufficient permissions by default (e.g., via the Editor role) or confuse Cloud Deploy permissions with Cloud Run permissions, leading them to select the Cloud Run Admin role instead of the specific Cloud Deploy Developer role.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add the Cloud Deploy Developer IAM role to the Cloud Build service account.

The Cloud Build service account (typically the Compute Engine default service account or a custom service account) needs the Cloud Deploy Developer IAM role (roles/clouddeploy.developer) to create releases in Cloud Deploy. This role grants the necessary permissions, such as clouddeploy.releases.create, which are required for the Cloud Build trigger to successfully create a release after building and pushing the Docker image. Without this role, the pipeline fails with a permission error, making option A the correct resolution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Add the Cloud Deploy Developer IAM role to the Cloud Build service account.

    Why this is correct

    Granting the Cloud Deploy Developer role to the Cloud Build service account supplies the missing `clouddeploy.releases.create` permission, which the trigger's build step requires when invoking Cloud Deploy to create a release. This directly satisfies the stem's constraint: the service account currently lacks permission to create releases.

  • ✗

    Verify that the cloudbuild.yaml file contains the correct steps.

    Why it's wrong here

    The cloudbuild.yaml steps already run successfully up to release creation, so the syntax is not the fault; the failure is authorisation. It is tempting because misconfigured build steps commonly cause pipeline failures, and would be correct if a step were missing or malformed.

  • ✗

    Enable the Cloud Deploy API for the project.

    Why it's wrong here

    The error is an IAM permission failure, not a disabled API; enabling Cloud Deploy changes nothing about the service account's roles. It is tempting because API enablement is a common first fix, and would be correct if the error stated the Cloud Deploy API was not enabled in the project.

  • ✗

    Grant the Cloud Build service account the Cloud Run Admin role.

    Why it's wrong here

    Cloud Run Admin governs deploying and managing Cloud Run services, not Cloud Deploy releases, so it cannot satisfy the create-release permission the pipeline needs. It tempts because Cloud Deploy targets Cloud Run runtimes, but the required role is Cloud Deploy Releaser (roles/clouddeploy.releaser) on the pipeline's service account.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.