Google Associate Cloud EngineerConfiguring access and securityMedium

A data analytics team requires a dedicated service account to run batch jobs on Compute Engine instances. This service account needs to read data from specific BigQuery datasets and write results to a Cloud Storage bucket. Which two IAM roles should you assign to this service account, adhering to the principle of least privilege?

  1. Aroles/bigquery.admin and roles/storage.admin
  2. Broles/bigquery.dataViewer and roles/storage.objectCreator
  3. Croles/bigquery.dataViewer and roles/storage.objectAdmin
  4. Droles/bigquery.user and roles/storage.objectCreator
Show answer & explanation

Correct answer: B. roles/bigquery.dataViewer and roles/storage.objectCreator

The 'BigQuery Data Viewer' role provides read-only access to BigQuery data, satisfying the 'read data' requirement. The 'Storage Object Creator' role allows writing new objects to a bucket, fulfilling the 'write results' requirement without granting excessive delete or management permissions.

Why the other options are wrong

  • A. roles/bigquery.admin and roles/storage.admin grant full administrative control, which is highly permissive and violates the principle of least privilege for a batch job.
  • C. roles/storage.objectAdmin grants delete and manage permissions, which is more than 'write results' requires, violating least privilege.
  • D. roles/bigquery.user has broader permissions than just reading data, including running queries and creating datasets, which might be more than needed. roles/storage.objectCreator is appropriate.

Least Privilege for Service Accounts

The security principle of granting a service account only the minimum necessary permissions to perform its intended function, reducing potential security risks.

  • Avoid using primitive roles (Owner, Editor, Viewer) for service accounts.
  • Use predefined roles that match specific tasks.
  • Create custom roles if predefined roles are too broad.

Memory trick: Give your service account only the keys it needs, no extra access, no security seeds.

More Configuring access and security questions