easyMultiple Choice
PDE Practice Question: Refer to the exhibit
Exhibit
Refer to the exhibit.
```json
{
"error": "denied: permission denied for us-central1-docker.pkg.dev/my-project/my-repo/my-model:latest"
}
```Refer to the exhibit. A Cloud Build step fails when pushing a Docker image to Artifact Registry. What is the missing IAM role for the Cloud Build service account?
⚠ Common exam trap
Google Cloud often tests the distinction between Artifact Registry and Container Registry roles, and the trap here is that candidates confuse `roles/containerregistry.admin` (for Container Registry) with the correct Artifact Registry role, or assume that Cloud Build's own editor role includes artifact push permissions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
roles/artifactregistry.writer
The Cloud Build service account needs the `roles/artifactregistry.writer` role to push Docker images to Artifact Registry. This role grants the necessary permissions to upload artifacts, including images, to the registry. Without it, the build step fails with an authorization error.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
roles/artifactregistry.writer
Why this is correct
roles/artifactregistry.writer grants the push permission Cloud Build requires to upload image layers to the repository. Without it, the step fails with a permission denied error, so this role directly resolves the failing push described in the exhibit.
- ✗
roles/containerregistry.admin
Why it's wrong here
roles/containerregistry.admin applies to the legacy Container Registry service, not Artifact Registry repositories, so the push is still denied. It is tempting because it is the obvious image-push role, and would be correct if the build targeted gcr.io rather than an Artifact Registry repository.
- ✗
roles/storage.objectCreator
Why it's wrong here
roles/storage.objectCreator grants writes to Cloud Storage buckets, not Artifact Registry repositories, so the Docker push remains unauthorised. It is tempting because Artifact Registry historically stored images in GCS-backed buckets, and would be correct if the build were uploading objects to a Cloud Storage bucket instead.
- ✗
roles/cloudbuild.builds.editor
Why it's wrong here
roles/cloudbuild.builds.editor governs Cloud Build job creation and execution, not Artifact Registry repository writes, so the push still fails. It is tempting because it is the natural Cloud Build role, and would be correct if the failure were in triggering or managing builds rather than authenticating the image push.
About these practice questions
One of 747 original PDE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PDE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PDE exam.