Google Associate Cloud EngineerConfiguring access and securityMedium

A development team is working on a new application that needs to create and manage virtual machine instances on Google Compute Engine. They have a dedicated service account for this application. To ensure that the service account can only perform actions related to Compute Engine instances within their project and nothing else, which IAM role should be assigned?

  1. ACompute Instance Admin (v1)
  2. BCompute Network Admin
  3. CProject Owner
  4. DCompute Viewer
Show answer & explanation

Correct answer: A. Compute Instance Admin (v1)

The Compute Instance Admin (v1) role grants full control over Compute Engine instances, including creation, deletion, and modification, which is precisely what the development team needs for managing VMs. It adheres to the principle of least privilege by limiting access to instances only.

Why the other options are wrong

  • B. This role manages network resources, not Compute Engine instances directly.
  • C. This role grants full control over all resources in the project, which violates the principle of least privilege.
  • D. This role only provides read-only access to Compute Engine resources, which is insufficient for creating and managing instances.

Compute Instance Admin (v1) Role

The Compute Instance Admin (v1) role grants full control over Google Compute Engine virtual machine instances.

  • Allows creation, deletion, modification, and management of VM instances.
  • Does not grant access to network, storage, or other Compute Engine resources beyond instances.
  • Is a common role for users or service accounts managing VMs.

Memory trick: Administering VMs means you need the keys to the instances.

More Configuring access and security questions