Courseiva
Storing the Data →mediumMultiple Choice

PDE Storing the Data Practice Question

A company is designing a data lake on Cloud Storage with three zones: raw, curated, and processed. They need to enforce data governance by restricting access to each zone using IAM. Which approach should they take?

⚠ Common exam trap

A common misconception is that folders within a single Cloud Storage bucket can serve as effective security boundaries. However, folders are just a naming convention (prefixes) and do not provide native access control isolation without complex IAM conditions or ACLs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create three separate buckets, one per zone, and assign IAM roles per bucket

Cloud Storage buckets are the fundamental access boundary for IAM policies. By creating three separate buckets (raw, curated, processed), you can assign distinct IAM roles (e.g., roles/storage.objectViewer, roles/storage.objectAdmin) per bucket, ensuring that users or service accounts only have access to the specific zone they are authorized for. This approach aligns with the principle of least privilege and avoids the complexity and limitations of IAM conditions or object-level ACLs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a single bucket with folders for each zone, and use IAM conditions to restrict access

    Why it's wrong here

    IAM conditions on a single bucket cannot reliably separate prefix-level zones, and inherited bucket roles leak access across folders. Conditions suit attribute-based restrictions such as time or resource tags; distinct buckets with dedicated IAM bindings give the required zone isolation.

  • ✗

    Use Cloud Storage lifecycle rules to move objects between zones

    Why it's wrong here

    Lifecycle rules relocate or delete objects by age and storage class; they grant no access control whatsoever. They suit cost tiering and retention, not governance, so they leave raw, curated and processed zones without the IAM-enforced separation the design requires.

  • ✗

    Use a single bucket and rely on object ACLs

    Why it's wrong here

    Object ACLs operate per object and cannot express zone-level governance boundaries; they also conflict with uniform bucket-level access. ACLs suit granular per-object sharing in legacy setups, whereas separate buckets with IAM policies enforce distinct zone permissions cleanly.

  • ✓

    Create three separate buckets, one per zone, and assign IAM roles per bucket

    Why this is correct

    Separate buckets per zone let IAM policies and roles be scoped at bucket level, giving clean, enforceable isolation between raw, curated and processed data. Bucket-level IAM is the granularity Cloud Storage supports, so this directly satisfies the zone-restriction governance requirement.

About these practice questions

This PDE question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PDE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PDE exam.