Courseiva
easyMultiple Choice

PDE Practice Question: Refer to the exhibit

Exhibit

Refer to the exhibit.
```json
{
  "error": "denied: permission denied for us-central1-docker.pkg.dev/my-project/my-repo/my-model:latest"
}
```

Refer to the exhibit. A Cloud Build step fails when pushing a Docker image to Artifact Registry. What is the missing IAM role for the Cloud Build service account?

⚠ Common exam trap

Google Cloud often tests the distinction between Artifact Registry and Container Registry roles, and the trap here is that candidates confuse `roles/containerregistry.admin` (for Container Registry) with the correct Artifact Registry role, or assume that Cloud Build's own editor role includes artifact push permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

roles/artifactregistry.writer

The Cloud Build service account needs the `roles/artifactregistry.writer` role to push Docker images to Artifact Registry. This role grants the necessary permissions to upload artifacts, including images, to the registry. Without it, the build step fails with an authorization error.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    roles/artifactregistry.writer

    Why this is correct

    roles/artifactregistry.writer grants the push permission Cloud Build requires to upload image layers to the repository. Without it, the step fails with a permission denied error, so this role directly resolves the failing push described in the exhibit.

  • ✗

    roles/containerregistry.admin

    Why it's wrong here

    roles/containerregistry.admin applies to the legacy Container Registry service, not Artifact Registry repositories, so the push is still denied. It is tempting because it is the obvious image-push role, and would be correct if the build targeted gcr.io rather than an Artifact Registry repository.

  • ✗

    roles/storage.objectCreator

    Why it's wrong here

    roles/storage.objectCreator grants writes to Cloud Storage buckets, not Artifact Registry repositories, so the Docker push remains unauthorised. It is tempting because Artifact Registry historically stored images in GCS-backed buckets, and would be correct if the build were uploading objects to a Cloud Storage bucket instead.

  • ✗

    roles/cloudbuild.builds.editor

    Why it's wrong here

    roles/cloudbuild.builds.editor governs Cloud Build job creation and execution, not Artifact Registry repository writes, so the push still fails. It is tempting because it is the natural Cloud Build role, and would be correct if the failure were in triggering or managing builds rather than authenticating the image push.

About these practice questions

One of 747 original PDE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PDE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PDE exam.