Courseiva

PMLE Automating and Orchestrating ML Pipelines Practice Question

An ML engineer is designing a Vertex AI pipeline that includes a custom training component. The component must read training data from a Cloud Storage bucket and write the trained model to a Vertex AI Model Registry. The engineer wants to ensure the component can access these resources securely. Which two configurations should the engineer implement? (Choose two.)

⚠ Common exam trap

The trap here is thinking that embedding credentials or using environment variables is necessary, when in fact Vertex AI Pipelines uses the pipeline's service account for authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Specify the pipeline's service account when submitting the pipeline run.

To securely access Cloud Storage and Vertex AI Model Registry, the pipeline's service account must have the required IAM roles, and that service account must be specified when submitting the pipeline run. This ensures the component authenticates with the correct permissions without embedding credentials.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the default Compute Engine service account for all pipeline runs.

    Why it's wrong here

    The default Compute Engine service account often has broad permissions, which violates the principle of least privilege. Using it for all pipeline runs can lead to excessive access and potential security risks. It is better to create a dedicated service account with only the necessary permissions for the pipeline's tasks. Relying on the default service account is not a recommended practice for secure ML pipelines.

  • ✗

    Set the component's environment variable GOOGLE_APPLICATION_CREDENTIALS to point to a mounted secret.

    Why it's wrong here

    While this is a common pattern in some environments, in Vertex AI Pipelines the recommended approach is to use the pipeline's service account. Mounting a secret with credentials adds complexity and potential for leakage. The pipeline service account automatically provides credentials to the component. Using GOOGLE_APPLICATION_CREDENTIALS is unnecessary and less secure than leveraging the built-in service account.

  • ✓

    Specify the pipeline's service account when submitting the pipeline run.

    Why this is correct

    When submitting a pipeline run, you can specify a service account that the pipeline will use. This service account's permissions determine what resources the components can access. By specifying a service account with the right roles for Cloud Storage and Vertex AI, the engineer ensures secure access. This is the correct way to manage authentication for pipeline components in Vertex AI.

  • ✗

    Embed a service account key file in the component's container image.

    Why it's wrong here

    Embedding a service account key in a container image is a security anti-pattern. It exposes credentials in the image, which can be leaked or misused. Vertex AI Pipelines components should use the pipeline's service account for authentication, which is managed by Google Cloud IAM. This approach avoids key management and follows the principle of least privilege.

  • ✓

    Grant the Vertex AI Pipelines service account the necessary IAM roles for Cloud Storage and Vertex AI.

    Why this is correct

    The pipeline runs under a service account, which must have permissions to read from Cloud Storage and write to Vertex AI Model Registry. Granting appropriate IAM roles, such as Storage Object Viewer and Vertex AI User, ensures the component can access these resources. This is a fundamental security practice for pipeline components. Without these permissions, the component will fail with access denied errors.

About these practice questions

This PMLE question is part of Courseiva's 775-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PMLE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PMLE exam.