Professional Cloud Security EngineerConfiguring access within a cloud solution environmentEasy

A security engineer needs to configure a service account that will be used by an external third-party application to publish messages to a specific Pub/Sub topic named `projects/my-project/topics/data-ingest`. The service account should only have the minimum necessary permissions for this task and nothing more. Which IAM role should be granted to the service account?

  1. Aroles/iam.serviceAccountUser
  2. Broles/editor
  3. Croles/pubsub.publisher
  4. Droles/pubsub.viewer
Show answer & explanation

Correct answer: C. roles/pubsub.publisher

The `roles/pubsub.publisher` role provides permissions to publish messages to a Pub/Sub topic. This adheres to the principle of least privilege as it grants only the necessary permission for the specified task without allowing broader actions like editing or viewing, or general service account impersonation.

Why the other options are wrong

  • A. The `roles/iam.serviceAccountUser` role allows a user to impersonate a service account, not for the service account itself to publish messages to Pub/Sub.
  • B. The `roles/editor` role gives broad permissions across a project and violates the principle of least privilege.
  • D. The `roles/pubsub.viewer` role only allows viewing Pub/Sub resources, not publishing messages.

Pub/Sub Publisher Role

An IAM predefined role that grants permissions to publish messages to Google Cloud Pub/Sub topics.

  • Specifically designed for publishing messages.
  • Adheres to the principle of least privilege for message producers.
  • Does not grant permissions to create topics, subscribe, or view messages.

Memory trick: Publisher Posts Pub/Sub Properly.

More Configuring access within a cloud solution environment questions