Courseiva

Sharing Vertex AI Model via IAM

A data scientist wants to share a trained model with the team for review before deployment. The model is stored in Vertex AI Model Registry. What is the recommended way to grant the team read access to the model?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Grant the IAM role 'roles/aiplatform.viewer' to the team members on the project.

The 'roles/aiplatform.viewer' IAM role grants read-only access to Vertex AI resources, including models in the Model Registry. Option A is incorrect because 'roles/aiplatform.admin' grants full administrative access, which is too broad for read-only needs. Option B is wrong because exporting the model and sharing via a shared drive bypasses version control and security best practices. Option D is incorrect because Cloud Storage bucket ACLs control access to the underlying bucket, not to the Vertex AI Model Registry; the model is managed through Vertex AI IAM.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Grant the IAM role 'roles/aiplatform.admin' to the team members.

    Why it's wrong here

    Granting `roles/aiplatform.admin` gives the team full control over Vertex AI resources, including deletion and deployment, exceeding the read-only requirement for review. It is tempting because that role genuinely suits platform administrators managing the whole Vertex AI estate, but here it violates least privilege; `roles/aiplatform.viewer` provides the needed read access.

  • ✗

    Export the model as a local file and share it via a shared drive.

    Why it's wrong here

    Exporting the model bypasses Vertex AI Model Registry's IAM entirely, so the team loses registry metadata, versioning and lineage; sharing a file grants no registry read access. It is tempting because exporting suits offline inference or migration between platforms, where a portable artefact is genuinely required.

  • ✓

    Grant the IAM role 'roles/aiplatform.viewer' to the team members on the project.

    Why this is correct

    Granting `roles/aiplatform.viewer` at project level gives team members read-only access to all Vertex AI resources, including registered models in Model Registry, satisfying the review-before-deployment requirement. It is the least-privilege predefined role that permits viewing models without granting deploy or edit permissions.

  • ✗

    Add the team members to the Cloud Storage bucket ACL with 'READER' access.

    Why it's wrong here

    Bucket ACLs govern object-level access to the underlying artefacts, not Model Registry entries, so team members still cannot view or review the registered model. It tempts because Cloud Storage ACLs are the standard mechanism for sharing raw model files directly, which would be correct if the model were stored only as artefacts rather than registered in Vertex AI Model Registry.

About these practice questions

One of 775 original PMLE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PMLE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PMLE exam.