Google Associate Cloud EngineerConfiguring access and securityMedium
A data analytics team requires a dedicated service account to run batch jobs on Compute Engine instances. This service account needs to read data from specific BigQuery datasets and write results to a Cloud Storage bucket. Which two IAM roles should you assign to this service account, adhering to the principle of least privilege?
- Aroles/bigquery.admin and roles/storage.admin
- Broles/bigquery.dataViewer and roles/storage.objectCreator
- Croles/bigquery.dataViewer and roles/storage.objectAdmin
- Droles/bigquery.user and roles/storage.objectCreator
Show answer & explanationAnswer & explanation
Correct answer: B. roles/bigquery.dataViewer and roles/storage.objectCreator
The 'BigQuery Data Viewer' role provides read-only access to BigQuery data, satisfying the 'read data' requirement. The 'Storage Object Creator' role allows writing new objects to a bucket, fulfilling the 'write results' requirement without granting excessive delete or management permissions.
Why the other options are wrong
- A. roles/bigquery.admin and roles/storage.admin grant full administrative control, which is highly permissive and violates the principle of least privilege for a batch job.
- C. roles/storage.objectAdmin grants delete and manage permissions, which is more than 'write results' requires, violating least privilege.
- D. roles/bigquery.user has broader permissions than just reading data, including running queries and creating datasets, which might be more than needed. roles/storage.objectCreator is appropriate.
Least Privilege for Service Accounts
The security principle of granting a service account only the minimum necessary permissions to perform its intended function, reducing potential security risks.
- Avoid using primitive roles (Owner, Editor, Viewer) for service accounts.
- Use predefined roles that match specific tasks.
- Create custom roles if predefined roles are too broad.
Memory trick: Give your service account only the keys it needs, no extra access, no security seeds.