Courseiva

Google PCA Design for security and compliance Practice Question

A startup wants to grant a new employee read-only access to view all Compute Engine instances in a project. What is the minimum IAM role they should assign?

⚠ Common exam trap

Watch out — candidates often confuse roles/compute.viewer with roles/iam.securityReviewer, thinking the latter provides broader read access, but it lacks the specific Compute Engine permissions needed to view instances.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

roles/compute.viewer

The roles/compute.viewer role grants read-only access to Compute Engine resources, including the ability to list and view instances, without allowing modifications. This is the minimum IAM role that satisfies the requirement for read-only access to all Compute Engine instances in a project, as it provides the necessary permissions (e.g., compute.instances.list, compute.instances.get) without granting broader project-level or write permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    roles/owner

    Why it's wrong here

    roles/owner grants full control over all project resources, including IAM policy changes, far exceeding read-only Compute Engine visibility. It suits project owners administering billing, permissions and every service, not an employee who only needs to list instances.

  • ✓

    roles/compute.viewer

    Why this is correct

    roles/compute.viewer grants read-only permission to list and get Compute Engine instances, resources, and related metadata across the project. It satisfies the least-privilege requirement without granting the modify or delete capabilities included in broader roles such as compute.admin.

  • ✗

    roles/iam.securityReviewer

    Why it's wrong here

    roles/iam.securityReviewer grants read access to IAM policies and security settings, not to Compute Engine instances, so listing instances fails. It is tempting as a read-only security role, but viewing all instances requires roles/compute.viewer, which is the minimum role for that resource.

  • ✗

    roles/compute.admin

    Why it's wrong here

    roles/compute.admin grants full control over Compute Engine resources, including create, delete and modify, so it exceeds the read-only requirement and violates least privilege. It is tempting because it guarantees visibility of every instance, but roles/compute.viewer already provides that read-only access.

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.