Courseiva

PMLE Scaling Prototypes into ML Models Practice Question

You are preparing a Vertex AI custom training job that uses a custom Docker image built on top of the PyTorch pre-built training container. The image must be able to read training data from a Cloud Storage bucket without embedding credentials in the image. You want the job to run on a single NVIDIA T4 GPU. Which approach should you take?

⚠ Common exam trap

It's easy for candidates to confuse the Vertex AI Custom Code Service Agent, which acts on behalf of the Vertex AI service, with the user-managed service account that actually runs inside the training container and accesses Cloud Storage.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Specify a user-managed service account with the Storage Object Viewer role when submitting the custom job, and let the container use Application Default Credentials to read from Cloud Storage.

A user-managed service account attached to the custom job provides the identity that the training container uses. Vertex AI injects credentials via the metadata server, so Application Default Credentials in the container can authenticate to Cloud Storage. Granting the least-privilege Storage Object Viewer role satisfies the data access requirement without embedding keys. The job can also be configured with a single T4 GPU accelerator to meet the compute requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Mount the Cloud Storage bucket as a local file system using Cloud Storage FUSE inside the container and rely on the bucket's default IAM permissions for anonymous access.

    Why it's wrong here

    Cloud Storage FUSE still requires authentication and authorization through IAM; buckets do not grant anonymous access by default. Mounting a bucket does not remove the need for credentials, and it adds complexity and potential performance overhead for training data. This option also does not address how the container obtains credentials, so it fails the requirement of avoiding embedded secrets.

  • ✗

    Hard-code a service account JSON key file into the Docker image and set GOOGLE_APPLICATION_CREDENTIALS in the Dockerfile.

    Why it's wrong here

    Embedding a long-lived service account key in a container image is a security anti-pattern and violates Google Cloud best practices. Vertex AI custom training jobs automatically provide credentials through the attached service account and the metadata server, so hard-coding keys is unnecessary, increases the risk of credential leakage, and complicates key rotation. It also does not address the GPU requirement.

  • ✓

    Specify a user-managed service account with the Storage Object Viewer role when submitting the custom job, and let the container use Application Default Credentials to read from Cloud Storage.

    Why this is correct

    When you submit a Vertex AI custom training job, you can attach a user-managed service account. The container then obtains credentials from the Compute Engine metadata server through Application Default Credentials. Granting that service account the Storage Object Viewer role allows the training code to read objects from Cloud Storage without embedding keys, and the job can be configured with a single T4 GPU accelerator.

  • ✗

    Grant the Vertex AI Custom Code Service Agent the Storage Object Viewer role and let the training container use the default credentials from the metadata server.

    Why it's wrong here

    The Vertex AI Custom Code Service Agent is used by Vertex AI to pull your container image and access other resources on your behalf, but it is not the identity that runs inside the training container. The code inside the container uses the user-managed service account specified for the custom job, so granting permissions to the service agent would not give the training code access to Cloud Storage.

About these practice questions

Courseiva writes every PMLE question from scratch — 775 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PMLE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PMLE exam.