Google PCA Design for security and compliance Practice Question
A startup wants to grant a new employee read-only access to view all Compute Engine instances in a project. What is the minimum IAM role they should assign?
⚠ Common exam trap
Watch out — candidates often confuse roles/compute.viewer with roles/iam.securityReviewer, thinking the latter provides broader read access, but it lacks the specific Compute Engine permissions needed to view instances.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
roles/compute.viewer
The roles/compute.viewer role grants read-only access to Compute Engine resources, including the ability to list and view instances, without allowing modifications. This is the minimum IAM role that satisfies the requirement for read-only access to all Compute Engine instances in a project, as it provides the necessary permissions (e.g., compute.instances.list, compute.instances.get) without granting broader project-level or write permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
roles/owner
Why it's wrong here
roles/owner grants full control over all project resources, including IAM policy changes, far exceeding read-only Compute Engine visibility. It suits project owners administering billing, permissions and every service, not an employee who only needs to list instances.
- ✓
roles/compute.viewer
Why this is correct
roles/compute.viewer grants read-only permission to list and get Compute Engine instances, resources, and related metadata across the project. It satisfies the least-privilege requirement without granting the modify or delete capabilities included in broader roles such as compute.admin.
- ✗
roles/iam.securityReviewer
Why it's wrong here
roles/iam.securityReviewer grants read access to IAM policies and security settings, not to Compute Engine instances, so listing instances fails. It is tempting as a read-only security role, but viewing all instances requires roles/compute.viewer, which is the minimum role for that resource.
- ✗
roles/compute.admin
Why it's wrong here
roles/compute.admin grants full control over Compute Engine resources, including create, delete and modify, so it exceeds the read-only requirement and violates least privilege. It is tempting because it guarantees visibility of every instance, but roles/compute.viewer already provides that read-only access.
Go deeper
Related to this question
Learn chapter
Google Kubernetes Engine (GKE)
Key term
Project
A project is a temporary endeavor with a defined beginning and end, undertaken to create a unique product, service, or result, managed through specific processes in IT environments.
Key term
View
A view is a saved query in a database that acts like a virtual table, letting you see specific data without storing it separately.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.