Courseiva

Google PCA Designing for Security and Compliance Practice Question

Your company is designing a secure architecture for a new application on Google Cloud. They need to ensure that service accounts used by the application have only the necessary permissions, and that any use of those service accounts is auditable. Which two actions should they take? (Choose two.)

⚠ Common exam trap

The trap here is assuming that Admin Activity audit logs capture all service account usage, when Data Access logs are needed for read/write operations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Grant the service accounts predefined roles that include only the required permissions, and avoid using basic roles like Editor.

Least privilege is achieved by granting only the necessary predefined roles and avoiding basic roles. Auditability of service account usage requires enabling Data Access audit logs, which are not enabled by default. Together, these actions ensure that service accounts have minimal permissions and that their actions are logged for auditing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a custom role that includes all permissions the application might need in the future, to avoid frequent updates.

    Why it's wrong here

    Creating a custom role with all potentially needed permissions violates least privilege. It grants excessive permissions that could be exploited if the service account is compromised. Custom roles should be tightly scoped to current needs and updated as requirements change. This action increases risk rather than reducing it.

  • ✗

    Use service account keys and rotate them every 90 days to ensure secure authentication.

    Why it's wrong here

    Service account keys are a security risk because they can be leaked or stolen. Google recommends avoiding keys and using alternatives like Workload Identity Federation or attached service accounts. Rotating keys does not eliminate the risk of key compromise. This action does not align with best practices for secure service account usage.

  • ✗

    Assign the service accounts the Project Editor role to simplify permission management.

    Why it's wrong here

    The Project Editor role grants broad permissions across many services, violating least privilege. It simplifies management at the cost of security. This action would give the service accounts far more access than needed, increasing the blast radius of a compromise. It is not a recommended practice for secure architecture.

  • ✓

    Grant the service accounts predefined roles that include only the required permissions, and avoid using basic roles like Editor.

    Why this is correct

    Using predefined roles that contain only the necessary permissions follows the principle of least privilege. Basic roles like Editor grant broad permissions across many services, violating least privilege. This action reduces the risk of excessive access and is a recommended practice for secure architecture.

  • ✓

    Enable Data Access audit logs for all services used by the application to capture service account activity.

    Why this is correct

    Data Access audit logs record API calls that read or modify data, including actions performed by service accounts. Enabling them for relevant services provides the required auditability. Admin Activity logs are enabled by default, but Data Access logs must be explicitly enabled. This action ensures service account usage is auditable.

About these practice questions

Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.