Courseiva

PDE Maintaining and Automating Data Workloads Practice Question

A data platform team wants to grant a service account the ability to run BigQuery jobs and read data in a specific dataset, while ensuring it cannot create or delete datasets. Which IAM approach satisfies this with least privilege?

⚠ Common exam trap

The trap here is assuming a single predefined role covers both running jobs and reading a dataset, when job creation and data access are granted at different scopes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Grant bigquery.jobs.create at the project level and BigQuery Data Viewer on the specific dataset.

BigQuery separates the permission to run jobs from the permission to read data. Job creation is a project-level capability, so the service account needs bigquery.jobs.create at the project scope. Reading data can be scoped to the specific dataset with BigQuery Data Viewer, which confines access to that dataset and excludes dataset creation or deletion. Combining these two grants achieves the read-and-run requirement with least privilege.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Grant the BigQuery Admin role on the dataset.

    Why it's wrong here

    BigQuery Admin includes permissions to create, update, and delete datasets and tables, which directly violates the requirement that the service account cannot create or delete datasets. It is far broader than the task needs. Least privilege calls for separating job execution permission from data access permission.

  • ✗

    Grant the BigQuery Data Editor role at the project level.

    Why it's wrong here

    BigQuery Data Editor allows reading and modifying data across the project, which is broader than the read-only requirement and does not by itself guarantee job creation. It also omits control over job submission in the intended way. The scope and the permission set both exceed what the scenario needs.

  • ✓

    Grant bigquery.jobs.create at the project level and BigQuery Data Viewer on the specific dataset.

    Why this is correct

    Job creation permission is granted at the project level because jobs are project-scoped resources, while data read access is granted on the dataset to limit exposure. This combination lets the service account run jobs that read the target dataset without granting rights over other datasets. It excludes dataset creation and deletion permissions, satisfying least privilege.

  • ✗

    Grant the service account the BigQuery Data Viewer role at the project level.

    Why it's wrong here

    BigQuery Data Viewer grants read access to data, but it does not include the permissions needed to run query jobs, such as bigquery.jobs.create. The service account would be able to read tables directly but unable to submit jobs. It also applies project-wide, which is broader than needed for a single dataset.

About these practice questions

Courseiva writes every PDE question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PDE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PDE exam.