Google PCA Design for security and compliance Practice Question
Exhibit
Refer to the exhibit.
```bash
$ gcloud projects set-iam-policy my-project policy.json
Updated IAM policy for project [my-project].
$
```
Contents of policy.json:
```json
{
"bindings": [
{
"role": "roles/storage.objectViewer",
"members": [
"user:alice@example.com",
"serviceAccount:sa-bucket-reader@my-project.iam.gserviceaccount.com"
]
}
],
"etag": "BwVY3Y8Y8Y8="
}
```After executing the command, a security review reveals that the service account sa-bucket-reader can also list buckets in the project, which was not intended. What is the most likely cause?
⚠ Common exam trap
In Google PCA exams, the distinction between project-level and resource-level IAM roles is critical. The trap here is that candidates assume bucket-level IAM is the only way to grant bucket access, forgetting that project-level roles can also include bucket-related permissions like storage.buckets.list.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The service account has a project-level role that includes storage.list.
The service account sa-bucket-reader was able to list buckets in the project, which requires the storage.buckets.list permission. This permission is included in several predefined project-level roles, such as roles/storage.objectViewer or roles/storage.legacyBucketReader. If the service account was granted a project-level role that includes storage.buckets.list, it would have the unintended ability to list all buckets in the project, even if bucket-level IAM was configured to restrict access to specific buckets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The etag was incorrect, causing a concurrent modification.
Why it's wrong here
An incorrect etag causes the policy update request to be rejected as a concurrent modification, so no permission change occurs; it cannot grant listing. Etags suit optimistic concurrency control when multiple writers edit the same policy simultaneously.
- ✓
The service account has a project-level role that includes storage.list.
Why this is correct
Project-level roles like roles/storage.objectAdmin or roles/viewer include storage.buckets.list.
- ✗
The policy update failed due to a missing condition.
Why it's wrong here
A missing condition would cause the policy update to fail or apply too broadly, but listing buckets stems from a project-level role binding, not a condition. Conditions suit restricting existing permissions by resource attributes, not causing unintended enumeration.
- ✗
The service account also has bucket-level IAM roles.
Why it's wrong here
Bucket-level IAM roles grant actions only within a specific bucket; listing buckets is a project-level permission, so bucket roles cannot cause this. Bucket IAM suits scoping access to one bucket's objects, not granting project-wide enumeration.
Go deeper
Related to this question
Learn chapter
IAM Policies, Service Accounts, and Auditing
Key term
Project
A project is a temporary endeavor with a defined beginning and end, undertaken to create a unique product, service, or result, managed through specific processes in IT environments.
Key term
CAN
A CAN (Controller Area Network) is a robust vehicle bus standard designed to allow microcontrollers and devices to communicate with each other without a host computer.
About these practice questions
This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.