Professional Cloud Security EngineerConfiguring access within a cloud solution environmentHard

A security engineer needs to implement a custom role that grants permissions to manage only specific BigQuery datasets within a project, rather than all datasets. The custom role should allow users to create, update, and delete tables within these specific datasets, but not manage other datasets or other BigQuery resources. How should the permissions be defined for this custom role?

  1. AInclude `bigquery.tables.create`, `bigquery.tables.update`, `bigquery.tables.delete` and bind the role at the specific dataset level using IAM Conditions.
  2. BInclude `bigquery.datasets.update`, `bigquery.tables.create`, `bigquery.tables.update`, `bigquery.tables.delete` and bind the role at the project level.
  3. CInclude `bigquery.dataEditor` role and bind it to the specific datasets.
  4. DInclude `bigquery.datasets.get`, `bigquery.tables.create`, `bigquery.tables.update`, `bigquery.tables.delete` and bind the role at the specific dataset level.
Show answer & explanation

Correct answer: D. Include `bigquery.datasets.get`, `bigquery.tables.create`, `bigquery.tables.update`, `bigquery.tables.delete` and bind the role at the specific dataset level.

To manage tables within specific datasets, the user needs permissions related to tables (`bigquery.tables.create`, `update`, `delete`) and also the ability to view the dataset itself (`bigquery.datasets.get`). Critically, these permissions must be bound directly to the *specific datasets* (resource level) to ensure granularity and prevent access to other datasets or project-level resources.

Why the other options are wrong

  • A. While IAM Conditions can add further granularity, the primary mechanism for restricting access to specific datasets is to bind the role directly at the dataset resource level. `bigquery.datasets.get` is also needed to interact with the dataset, not just tables within it. Also, the question is about *defining* the custom role's permissions, not just the binding condition.
  • B. Binding at the project level would grant access to *all* datasets in the project, violating the 'only specific datasets' requirement. `bigquery.datasets.update` is too broad if only table management is needed within specific datasets.
  • C. `bigquery.dataEditor` is a predefined role that includes `bigquery.datasets.update` and other broad permissions, which might grant more than needed, and the question specifies a *custom role*.

Custom Role (Fine-grained BigQuery)

Custom roles allow defining specific sets of permissions tailored to exact requirements, enabling fine-grained access control to Google Cloud resources like BigQuery datasets and tables.

  • Define specific permissions (e.g., `bigquery.tables.create`).
  • Bind at the lowest possible resource level (e.g., dataset).
  • Adheres to the principle of least privilege.

Memory trick: Custom roles bind specific powers to specific data.

More Configuring access within a cloud solution environment questions