How Should You Grant Variable Cloud Storage Access from a VM?
You are developing an application that runs on a Compute Engine VM. The application needs to access data stored in Cloud Storage buckets in other Google Cloud projects. The required access to the buckets is variable. You need to provide access to these resources while following Google- recommended practices. What should you do?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests knowledge of modern GCP identity management by evaluating whether you will use deprecated access scopes, inappropriate delegation methods, or direct IAM bindings for flexible, least-privilege cross-project access.
Learn how to securely grant variable cross-project Cloud Storage access to a Compute Engine VM using IAM bindings on its service account, following Google-recommended least-privilege practices.
Candidates frequently select access scopes due to outdated training materials, but scopes grant overly broad permissions and violate current least-privilege standards.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Directly assigning IAM roles to the VM’s service account provides granular, least-privilege control over each target bucket. This approach natively supports variable access requirements across different projects without introducing unnecessary indirection. Google explicitly recommends service account IAM bindings as the standard mechanism for workload-to-resource authentication in PCSE scenarios.Why the Other Options Are Wrong
Access scopes (A) are legacy configuration options that grant broad, non-granular permissions and have been largely superseded by IAM. Domain-wide delegation (C) is designed for Google Workspace OAuth impersonation, not for authenticating GCP service accounts to Cloud Storage. Creating a group (D) adds administrative overhead and complicates audit trails when a single workload only requires direct, explicit role assignments.Community Comment Notes
Learners consistently emphasize that direct IAM assignment avoids unnecessary complexity while maintaining strict security boundaries. As one contributor noted, this approach 'provides the most secure and flexible way to manage access.' Others confirmed it aligns perfectly with least-privilege standards for professional cloud security exams.Official Reference
Exam Strategy
When configuring cross-project resource access in PCSE, always default to granting IAM roles directly to the workload’s service account rather than using legacy scopes or administrative delegation features. Reserve groups only for large-scale user provisioning where centralized management justifies the added complexity.
Frequently Asked Questions
Why are access scopes not recommended for Cloud Storage access?
Access scopes are legacy mechanisms that grant overly broad permissions. Modern GCP relies on IAM bindings for granular, least-privilege control.
Should I use groups instead of direct service account bindings?
Groups add unnecessary complexity for single-workload scenarios. Direct IAM bindings to the service account are simpler, more auditable, and Google-recommended.