hardMultiple Choice
PMLE Practice Question: A machine learning engineer needs to share a…
A machine learning engineer needs to share a trained model with the product team for integration. The model is stored in Cloud Storage, and the product team’s service account needs read access. The engineer wants to follow the principle of least privilege. Which IAM configuration should be used?
⚠ Common exam trap
Many exam-takers confuse the principle of least privilege with convenience, choosing a signed URL (Option A) because it seems simple, or selecting a project-level role (Option D) without realizing it grants access to all buckets, both of which violate the core requirement of minimal necessary permissions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant the product team's service account the roles/storage.objectViewer role at the bucket level.
Granting the product team's service account the roles/storage.objectViewer role at the bucket level provides read-only access to objects in that specific bucket, adhering to the principle of least privilege. This role allows the service account to list and read objects without granting broader permissions, such as modifying or deleting them, and scoping it to the bucket prevents unnecessary access to other buckets in the project.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Generate a signed URL with read access and share it with the product team.
Why it's wrong here
A signed URL grants temporary read access to anyone holding it, not persistent access tied to the service account's identity. It tempts because it avoids IAM changes, and would be correct for one-off downloads by an external party without a Google identity, not ongoing service integration.
- ✓
Grant the product team's service account the roles/storage.objectViewer role at the bucket level.
Why this is correct
Granting roles/storage.objectViewer at bucket level gives the service account read-only access to objects within that specific bucket, satisfying least privilege by avoiding project-wide permissions. This scopes access precisely to the shared model's location, unlike broader roles such as storage.objectAdmin or project-level grants that would exceed the required read capability.
- ✗
Grant the product team's service account the roles/storage.objectAdmin role at the bucket level.
Why it's wrong here
ObjectAdmin grants write, delete and ACL permissions on bucket objects, far beyond the read access required. It tempts because bucket-level scoping limits blast radius, and would be correct if the product team also needed to manage or overwrite model artefacts rather than only read them.
- ✗
Grant the product team's service account the roles/storage.objectViewer role at the project level.
Why it's wrong here
Project-level objectViewer grants read access to every bucket in the project, exceeding least privilege for one model. It tempts because it is simple and definitely works, and would be correct if the service account genuinely needed to read objects across multiple buckets rather than a single model file.
Go deeper
Related to this question
About these practice questions
One of 775 original PMLE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PMLE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PMLE exam.