Courseiva

PDE Maintaining and Automating Data Workloads Practice Question

A data engineer must give a Dataproc Serverless for Spark batch workload permission to read objects from a specific Cloud Storage bucket and write to a BigQuery dataset, following least privilege. The workload runs as a custom service account. Which approach should be used?

⚠ Common exam trap

The trap here is treating VPC Service Controls or basic project roles as substitutes for scoped IAM bindings, when perimeter policies only constrain access and basic roles grant far more than the workload needs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Grant the workload's service account `roles/storage.objectViewer` on the bucket and `roles/bigquery.dataEditor` on the dataset.

Least privilege in Google Cloud means binding predefined or custom roles to the narrowest resource scope that still satisfies the workload. Bucket-level object viewer and dataset-level data editor grant precisely the read and write operations the Spark job requires. Broad project roles, default service accounts, and perimeter controls either overshoot the needed permissions or fail to grant them at all.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Grant the workload's service account `roles/storage.objectViewer` on the bucket and `roles/bigquery.dataEditor` on the dataset.

    Why this is correct

    Attaching IAM roles at the bucket and dataset level scopes permissions to exactly the resources the Spark workload touches. `roles/storage.objectViewer` permits reading objects without delete or create rights, and `roles/bigquery.dataEditor` allows writing data while excluding dataset administration. This satisfies least privilege for a Dataproc Serverless workload running as a custom service account.

  • ✗

    Grant the workload's service account the basic `roles/editor` role on the project so both Cloud Storage and BigQuery calls succeed.

    Why it's wrong here

    The basic Editor role grants broad permissions across nearly every Google Cloud service in the project, far exceeding the read-a-bucket and write-a-dataset needs. It violates least privilege and would allow the workload to modify unrelated resources, which is not acceptable for a production data platform with security review requirements.

  • ✗

    Enable the Cloud Storage and BigQuery APIs and rely on the default Compute Engine service account attached to the Dataproc Serverless workload.

    Why it's wrong here

    The scenario specifies a custom service account, and the default Compute Engine service account typically carries broad project-level roles such as Editor. Depending on it neither scopes access to the specific bucket and dataset nor follows least privilege. It also couples the workload's identity to a shared default account, complicating auditing and rotation.

  • ✗

    Create a VPC Service Controls perimeter around the bucket and dataset and add the workload's service account to the access level.

    Why it's wrong here

    VPC Service Controls restrict data exfiltration across a perimeter boundary, but they do not grant the underlying IAM permissions needed to read objects or write rows. Adding a service account to an access level without IAM roles still results in permission denied errors, so this alone cannot enable the required reads and writes.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 747 original PDE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PDE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PDE exam.