Google PCA Designing for Security and Compliance Practice Question
Your company is designing a secure architecture for a new application on Google Cloud. They need to ensure that service accounts used by the application have only the necessary permissions, and that any use of those service accounts is auditable. Which two actions should they take? (Choose two.)
⚠ Common exam trap
The trap here is assuming that Admin Activity audit logs capture all service account usage, when Data Access logs are needed for read/write operations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant the service accounts predefined roles that include only the required permissions, and avoid using basic roles like Editor.
Least privilege is achieved by granting only the necessary predefined roles and avoiding basic roles. Auditability of service account usage requires enabling Data Access audit logs, which are not enabled by default. Together, these actions ensure that service accounts have minimal permissions and that their actions are logged for auditing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a custom role that includes all permissions the application might need in the future, to avoid frequent updates.
Why it's wrong here
Creating a custom role with all potentially needed permissions violates least privilege. It grants excessive permissions that could be exploited if the service account is compromised. Custom roles should be tightly scoped to current needs and updated as requirements change. This action increases risk rather than reducing it.
- ✗
Use service account keys and rotate them every 90 days to ensure secure authentication.
Why it's wrong here
Service account keys are a security risk because they can be leaked or stolen. Google recommends avoiding keys and using alternatives like Workload Identity Federation or attached service accounts. Rotating keys does not eliminate the risk of key compromise. This action does not align with best practices for secure service account usage.
- ✗
Assign the service accounts the Project Editor role to simplify permission management.
Why it's wrong here
The Project Editor role grants broad permissions across many services, violating least privilege. It simplifies management at the cost of security. This action would give the service accounts far more access than needed, increasing the blast radius of a compromise. It is not a recommended practice for secure architecture.
- ✓
Grant the service accounts predefined roles that include only the required permissions, and avoid using basic roles like Editor.
Why this is correct
Using predefined roles that contain only the necessary permissions follows the principle of least privilege. Basic roles like Editor grant broad permissions across many services, violating least privilege. This action reduces the risk of excessive access and is a recommended practice for secure architecture.
- ✓
Enable Data Access audit logs for all services used by the application to capture service account activity.
Why this is correct
Data Access audit logs record API calls that read or modify data, including actions performed by service accounts. Enabling them for relevant services provides the required auditability. Admin Activity logs are enabled by default, but Data Access logs must be explicitly enabled. This action ensures service account usage is auditable.
Go deeper
Related to this question
Learn chapter
Data Migration and Transfer Services
Key term
Service account
A service account is a special type of account used by an application or a virtual machine, rather than a human user, to authenticate and interact with cloud services and APIs securely.
Key term
Service
A service is a software component or system that performs a specific function and is available to be used by other programs or users over a network.
About these practice questions
Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.