How Should You Grant Variable Cloud Storage Access from a VM?

Cloud IAM & Service Accounts
Answer Correct answer: B — Grant IAM roles directly to the VM’s service account for each target bucket to enforce least privilege and support variable access.

You are developing an application that runs on a Compute Engine VM. The application needs to access data stored in Cloud Storage buckets in other Google Cloud projects. The required access to the buckets is variable. You need to provide access to these resources while following Google- recommended practices. What should you do?

  1. Limit the VMs access to the Cloud Storage buckets by setting the relevant access scope of the VM.
  2. Create IAM bindings for the VM’s service account and the required buckets that allow appropriate access to the data stored in the buckets. Correct Answer
  3. Grant the VM's service account access to the required buckets by using domain-wide delegation.
  4. Create a group and assign IAM bindings to the group for each bucket that the application needs to access. Assign the VM's service account to the group.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests knowledge of modern GCP identity management by evaluating whether you will use deprecated access scopes, inappropriate delegation methods, or direct IAM bindings for flexible, least-privilege cross-project access.

Learn how to securely grant variable cross-project Cloud Storage access to a Compute Engine VM using IAM bindings on its service account, following Google-recommended least-privilege practices.

Candidates frequently select access scopes due to outdated training materials, but scopes grant overly broad permissions and violate current least-privilege standards.

Community Discussion (3 comments)

MoAk 👍 1 Selected: B
well explained below
vamgcp 👍 2 Selected: B
Directly assigning IAM bindings to the VM's service account for each Cloud Storage bucket provides the most secure and flexible way to manage access to your data. This approach adheres to the principle of least privilege and allows you to adapt to changing access requirements with ease. While groups can be useful for managing permissions for multiple VMs, it adds an extra layer of complexity when dealing with a single application on one VM.
abdelrahman89 👍 1 Selected: B
Answer B

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Directly assigning IAM roles to the VM’s service account provides granular, least-privilege control over each target bucket. This approach natively supports variable access requirements across different projects without introducing unnecessary indirection. Google explicitly recommends service account IAM bindings as the standard mechanism for workload-to-resource authentication in PCSE scenarios.

Why the Other Options Are Wrong

Access scopes (A) are legacy configuration options that grant broad, non-granular permissions and have been largely superseded by IAM. Domain-wide delegation (C) is designed for Google Workspace OAuth impersonation, not for authenticating GCP service accounts to Cloud Storage. Creating a group (D) adds administrative overhead and complicates audit trails when a single workload only requires direct, explicit role assignments.

Community Comment Notes

Learners consistently emphasize that direct IAM assignment avoids unnecessary complexity while maintaining strict security boundaries. As one contributor noted, this approach 'provides the most secure and flexible way to manage access.' Others confirmed it aligns perfectly with least-privilege standards for professional cloud security exams.

Official Reference

Exam Strategy

When configuring cross-project resource access in PCSE, always default to granting IAM roles directly to the workload’s service account rather than using legacy scopes or administrative delegation features. Reserve groups only for large-scale user provisioning where centralized management justifies the added complexity.

Frequently Asked Questions

Why are access scopes not recommended for Cloud Storage access?

Access scopes are legacy mechanisms that grant overly broad permissions. Modern GCP relies on IAM bindings for granular, least-privilege control.

Should I use groups instead of direct service account bindings?

Groups add unnecessary complexity for single-workload scenarios. Direct IAM bindings to the service account are simpler, more auditable, and Google-recommended.

Related Analysis

← Back to PCSE Study Guide