Google Associate Cloud EngineerConfiguring access and securityEasy
A financial institution is deploying a new application on Google Cloud that processes highly sensitive customer data. They need to ensure that only authenticated and authorized users can access the application's resources and that all access attempts are logged for auditing purposes. The application uses a service account to interact with other Google Cloud services. Which IAM role should be granted to the service account to allow it to read data from a BigQuery dataset, while adhering to the principle of least privilege?
- ABigQuery Admin
- BBigQuery Data Viewer
- CProject Editor
- DBigQuery Data Editor
Show answer & explanationAnswer & explanation
Correct answer: B. BigQuery Data Viewer
The BigQuery Data Viewer role provides read-only access to BigQuery datasets, which aligns with the principle of least privilege for a service account that only needs to read data. This role does not grant permissions to modify or administer BigQuery resources.
Why the other options are wrong
- A. This role grants full administrative control over BigQuery resources, exceeding the required permissions.
- C. This role grants broad editing permissions across an entire project, violating the principle of least privilege for a specific data access requirement.
- D. This role grants permissions to edit data, which is more than what is required for read-only access.
BigQuery Data Viewer Role
The BigQuery Data Viewer role grants read-only access to BigQuery datasets and tables.
- Provides permissions to read data and metadata from BigQuery.
- Adheres to the principle of least privilege for data consumption.
- Does not allow modification or deletion of data or resources.
Memory trick: Only view what you need to see, nothing more, nothing less.