Google Associate Cloud EngineerConfiguring access and securityMedium
An organization uses Google Cloud Identity to manage its users. A new employee joins the data science team and needs access to a specific BigQuery dataset for analysis. According to the principle of least privilege, how should you grant this access?
- AGrant the user a custom role with permissions to read all BigQuery datasets in the organization.
- BAdd the user to a Google Group, and grant the Google Group the 'BigQuery Data Editor' role on the dataset.
- CGrant the user the 'BigQuery Admin' role at the project level.
- DAdd the user directly to the dataset's IAM policy with the 'BigQuery Data Viewer' role.
Show answer & explanationAnswer & explanation
Correct answer: D. Add the user directly to the dataset's IAM policy with the 'BigQuery Data Viewer' role.
Granting the 'BigQuery Data Viewer' role directly on the specific dataset provides read-only access to only that dataset, adhering to the principle of least privilege. Option C correctly identifies the most granular and least privileged approach.
Why the other options are wrong
- A. Granting a custom role with permissions to read *all* BigQuery datasets in the *organization* is too broad. The requirement is for a *specific* dataset, and 'organization' scope is much wider than needed.
- B. While using Google Groups is a good practice for managing multiple users, 'BigQuery Data Editor' allows modifying data, which is more than 'analysis' typically implies (usually read-only). Also, it should be 'Data Viewer' for least privilege.
- C. Granting 'BigQuery Admin' at the project level is highly permissive, violating the principle of least privilege as it gives administrative control over all BigQuery resources in the project, not just a specific dataset for viewing.
BigQuery Data Viewer Role
An IAM role for BigQuery that grants read-only access to a specific dataset, table, or view.
- Allows querying data but not modifying schema, data, or managing jobs.
- Useful for analysts or applications that only need to consume data.
- Can be granted at the dataset, table, or project level (though project level is less granular).
Memory trick: To see the data, grant the Viewer role on the specific dataset, no more, no less, just the exact asset.