Google PCA Design and plan a cloud solution architecture Practice Question
Exhibit
Refer to the exhibit.
gcloud compute instances create my-instance \
--zone=us-central1-a \
--machine-type=n1-standard-4 \
--image-family=ubuntu-2004-lts \
--image-project=ubuntu-os-cloud \
--boot-disk-size=50GB \
--boot-disk-type=pd-ssd \
--scopes=cloud-platform \
--service-account=my-sa@project.iam.gserviceaccount.com \
--tags=http-server,https-serverThe exhibit shows a command to create a Compute Engine instance. The instance is intended to run a web server that needs to access Cloud Storage buckets using its service account. However, the web server fails to read from a storage bucket. What is the most likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The service account lacks IAM permissions to read from Cloud Storage
The correct answer is D: the service account lacks IAM permissions to read from Cloud Storage. Even when a service account is properly attached to a Compute Engine instance, the instance's applications can only access Cloud Storage buckets if that service account has been granted the appropriate IAM roles (for example, roles/storage.objectViewer) on the bucket or project. The failure to read from the bucket is therefore most likely an authorization issue at the IAM layer rather than a configuration problem with the instance itself. Option A is not the cause because the scenario states the instance uses its service account, and even a missing attachment would be a different setup issue. Option B is incorrect because firewall tags like http-server and https-server govern inbound HTTP/HTTPS traffic, not outbound access to the Cloud Storage API. Option C is incorrect because the boot disk type (SSD vs. standard) has no bearing on Cloud Storage access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The service account is not attached to the instance
Why it's wrong here
If no service account is attached, the instance uses the default Compute Engine service account, which may lack Storage Object Viewer on the bucket, causing reads to fail. Attaching the intended service account and granting it bucket IAM roles resolves this. This option is correct whenever the instance genuinely lacks an attached service account.
- ✗
The tags http-server and https-server block outbound traffic
Why it's wrong here
The http-server and https-server tags are network tags that enable inbound firewall rules for web traffic; they do not restrict outbound traffic to Cloud Storage. Egress to Google APIs is governed by IAM permissions and access scopes. These tags would be relevant when configuring inbound HTTP or HTTPS access to the web server itself.
- ✗
The boot disk type is SSD, which is not compatible with Cloud Storage
Why it's wrong here
Boot disk type is unrelated to Cloud Storage access; SSD and standard persistent disks both support the same network and IAM permissions. The failure stems from the instance's identity or scopes, not its disk. SSD would be the correct choice when the requirement is higher disk throughput for the boot volume, not storage bucket access.
- ✓
The service account lacks IAM permissions to read from Cloud Storage
Why this is correct
The instance's attached service account has no IAM role granting storage.objects.get on the bucket, so Cloud Storage returns 403 regardless of network or scope settings. Access scopes only gate the API surface; IAM bindings authorise the actual read, making missing permissions the direct cause of the failure.
Go deeper
Related to this question
Learn chapter
Cloud Storage: Objects and Buckets
Key term
HTTPS
HTTPS (Hypertext Transfer Protocol Secure) is the secure version of HTTP that encrypts data between a web browser and a web server using SSL/TLS protocols.
Key term
HTTP
HTTP stands for Hypertext Transfer Protocol, the set of rules web browsers and servers use to communicate and transfer web pages over the internet.
About these practice questions
Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.