PDE Maintaining and Automating Data Workloads Practice Question
A data engineer must give a Dataproc Serverless for Spark batch workload permission to read objects from a specific Cloud Storage bucket and write to a BigQuery dataset, following least privilege. The workload runs as a custom service account. Which approach should be used?
⚠ Common exam trap
The trap here is treating VPC Service Controls or basic project roles as substitutes for scoped IAM bindings, when perimeter policies only constrain access and basic roles grant far more than the workload needs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant the workload's service account `roles/storage.objectViewer` on the bucket and `roles/bigquery.dataEditor` on the dataset.
Least privilege in Google Cloud means binding predefined or custom roles to the narrowest resource scope that still satisfies the workload. Bucket-level object viewer and dataset-level data editor grant precisely the read and write operations the Spark job requires. Broad project roles, default service accounts, and perimeter controls either overshoot the needed permissions or fail to grant them at all.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Grant the workload's service account `roles/storage.objectViewer` on the bucket and `roles/bigquery.dataEditor` on the dataset.
Why this is correct
Attaching IAM roles at the bucket and dataset level scopes permissions to exactly the resources the Spark workload touches. `roles/storage.objectViewer` permits reading objects without delete or create rights, and `roles/bigquery.dataEditor` allows writing data while excluding dataset administration. This satisfies least privilege for a Dataproc Serverless workload running as a custom service account.
- ✗
Grant the workload's service account the basic `roles/editor` role on the project so both Cloud Storage and BigQuery calls succeed.
Why it's wrong here
The basic Editor role grants broad permissions across nearly every Google Cloud service in the project, far exceeding the read-a-bucket and write-a-dataset needs. It violates least privilege and would allow the workload to modify unrelated resources, which is not acceptable for a production data platform with security review requirements.
- ✗
Enable the Cloud Storage and BigQuery APIs and rely on the default Compute Engine service account attached to the Dataproc Serverless workload.
Why it's wrong here
The scenario specifies a custom service account, and the default Compute Engine service account typically carries broad project-level roles such as Editor. Depending on it neither scopes access to the specific bucket and dataset nor follows least privilege. It also couples the workload's identity to a shared default account, complicating auditing and rotation.
- ✗
Create a VPC Service Controls perimeter around the bucket and dataset and add the workload's service account to the access level.
Why it's wrong here
VPC Service Controls restrict data exfiltration across a perimeter boundary, but they do not grant the underlying IAM permissions needed to read objects or write rows. Adding a service account to an access level without IAM roles still results in permission denied errors, so this alone cannot enable the required reads and writes.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 747 original PDE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PDE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PDE exam.