Courseiva

Google PCA Design and plan a cloud solution architecture Practice Question

Exhibit

Refer to the exhibit.

gcloud compute instances create my-instance \
    --zone=us-central1-a \
    --machine-type=n1-standard-4 \
    --image-family=ubuntu-2004-lts \
    --image-project=ubuntu-os-cloud \
    --boot-disk-size=50GB \
    --boot-disk-type=pd-ssd \
    --scopes=cloud-platform \
    --service-account=my-sa@project.iam.gserviceaccount.com \
    --tags=http-server,https-server

The exhibit shows a command to create a Compute Engine instance. The instance is intended to run a web server that needs to access Cloud Storage buckets using its service account. However, the web server fails to read from a storage bucket. What is the most likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The service account lacks IAM permissions to read from Cloud Storage

The correct answer is D: the service account lacks IAM permissions to read from Cloud Storage. Even when a service account is properly attached to a Compute Engine instance, the instance's applications can only access Cloud Storage buckets if that service account has been granted the appropriate IAM roles (for example, roles/storage.objectViewer) on the bucket or project. The failure to read from the bucket is therefore most likely an authorization issue at the IAM layer rather than a configuration problem with the instance itself. Option A is not the cause because the scenario states the instance uses its service account, and even a missing attachment would be a different setup issue. Option B is incorrect because firewall tags like http-server and https-server govern inbound HTTP/HTTPS traffic, not outbound access to the Cloud Storage API. Option C is incorrect because the boot disk type (SSD vs. standard) has no bearing on Cloud Storage access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The service account is not attached to the instance

    Why it's wrong here

    If no service account is attached, the instance uses the default Compute Engine service account, which may lack Storage Object Viewer on the bucket, causing reads to fail. Attaching the intended service account and granting it bucket IAM roles resolves this. This option is correct whenever the instance genuinely lacks an attached service account.

  • ✗

    The tags http-server and https-server block outbound traffic

    Why it's wrong here

    The http-server and https-server tags are network tags that enable inbound firewall rules for web traffic; they do not restrict outbound traffic to Cloud Storage. Egress to Google APIs is governed by IAM permissions and access scopes. These tags would be relevant when configuring inbound HTTP or HTTPS access to the web server itself.

  • ✗

    The boot disk type is SSD, which is not compatible with Cloud Storage

    Why it's wrong here

    Boot disk type is unrelated to Cloud Storage access; SSD and standard persistent disks both support the same network and IAM permissions. The failure stems from the instance's identity or scopes, not its disk. SSD would be the correct choice when the requirement is higher disk throughput for the boot volume, not storage bucket access.

  • ✓

    The service account lacks IAM permissions to read from Cloud Storage

    Why this is correct

    The instance's attached service account has no IAM role granting storage.objects.get on the bucket, so Cloud Storage returns 403 regardless of network or scope settings. Access scopes only gate the API surface; IAM bindings authorise the actual read, making missing permissions the direct cause of the failure.

About these practice questions

Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.