Professional Cloud Security EngineerConfiguring access within a cloud solution environmentEasy
A security engineer is configuring a service account for a new application that will access a Cloud SQL instance. The application requires read-only access to a specific database within the instance. To adhere to the principle of least privilege, the engineer wants to grant the most restrictive permissions possible. Which IAM role should be assigned to the service account?
- Aroles/cloudsql.client
- Broles/cloudsql.admin
- Croles/editor
- Droles/owner
Show answer & explanationAnswer & explanation
Correct answer: A. roles/cloudsql.client
The `roles/cloudsql.client` role grants permissions to connect to a Cloud SQL instance and perform client-side operations, which typically include read-only access to databases if the database-level permissions allow it. This is the most restrictive predefined role for client connectivity. The actual database permissions (e.g., SELECT on specific tables) would also need to be configured within the database itself.
Why the other options are wrong
- B. The `roles/cloudsql.admin` role grants administrative privileges over Cloud SQL instances, including creating, deleting, and modifying instances, which is excessive for read-only database access.
- C. The `roles/editor` role provides broad project-level permissions, far exceeding read-only access to a single database.
- D. The `roles/owner` role grants full control over the project and all its resources, a severe violation of the principle of least privilege.
Cloud SQL Client Role
An IAM role (`roles/cloudsql.client`) that grants permissions to connect to a Cloud SQL instance and perform client-side operations, often used for applications needing to interact with databases.
- Allows connection to Cloud SQL instances.
- Requires in-database permissions for specific database operations.
- Example of least privilege for application database access.
Memory trick: Client connects, Admin manages, Editor edits, Owner owns.