Google Associate Cloud EngineerConfiguring access and securityMedium

An organization uses Google Cloud Identity to manage its users. A new employee joins the data science team and needs access to a specific BigQuery dataset for analysis. According to the principle of least privilege, how should you grant this access?

  1. AGrant the user a custom role with permissions to read all BigQuery datasets in the organization.
  2. BAdd the user to a Google Group, and grant the Google Group the 'BigQuery Data Editor' role on the dataset.
  3. CGrant the user the 'BigQuery Admin' role at the project level.
  4. DAdd the user directly to the dataset's IAM policy with the 'BigQuery Data Viewer' role.
Show answer & explanation

Correct answer: D. Add the user directly to the dataset's IAM policy with the 'BigQuery Data Viewer' role.

Granting the 'BigQuery Data Viewer' role directly on the specific dataset provides read-only access to only that dataset, adhering to the principle of least privilege. Option C correctly identifies the most granular and least privileged approach.

Why the other options are wrong

  • A. Granting a custom role with permissions to read *all* BigQuery datasets in the *organization* is too broad. The requirement is for a *specific* dataset, and 'organization' scope is much wider than needed.
  • B. While using Google Groups is a good practice for managing multiple users, 'BigQuery Data Editor' allows modifying data, which is more than 'analysis' typically implies (usually read-only). Also, it should be 'Data Viewer' for least privilege.
  • C. Granting 'BigQuery Admin' at the project level is highly permissive, violating the principle of least privilege as it gives administrative control over all BigQuery resources in the project, not just a specific dataset for viewing.

BigQuery Data Viewer Role

An IAM role for BigQuery that grants read-only access to a specific dataset, table, or view.

  • Allows querying data but not modifying schema, data, or managing jobs.
  • Useful for analysts or applications that only need to consume data.
  • Can be granted at the dataset, table, or project level (though project level is less granular).

Memory trick: To see the data, grant the Viewer role on the specific dataset, no more, no less, just the exact asset.

More Configuring access and security questions