PDE Maintaining and Automating Data Workloads Practice Question
A data platform team wants to grant a service account the ability to run BigQuery jobs and read data in a specific dataset, while ensuring it cannot create or delete datasets. Which IAM approach satisfies this with least privilege?
⚠ Common exam trap
The trap here is assuming a single predefined role covers both running jobs and reading a dataset, when job creation and data access are granted at different scopes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant bigquery.jobs.create at the project level and BigQuery Data Viewer on the specific dataset.
BigQuery separates the permission to run jobs from the permission to read data. Job creation is a project-level capability, so the service account needs bigquery.jobs.create at the project scope. Reading data can be scoped to the specific dataset with BigQuery Data Viewer, which confines access to that dataset and excludes dataset creation or deletion. Combining these two grants achieves the read-and-run requirement with least privilege.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Grant the BigQuery Admin role on the dataset.
Why it's wrong here
BigQuery Admin includes permissions to create, update, and delete datasets and tables, which directly violates the requirement that the service account cannot create or delete datasets. It is far broader than the task needs. Least privilege calls for separating job execution permission from data access permission.
- ✗
Grant the BigQuery Data Editor role at the project level.
Why it's wrong here
BigQuery Data Editor allows reading and modifying data across the project, which is broader than the read-only requirement and does not by itself guarantee job creation. It also omits control over job submission in the intended way. The scope and the permission set both exceed what the scenario needs.
- ✓
Grant bigquery.jobs.create at the project level and BigQuery Data Viewer on the specific dataset.
Why this is correct
Job creation permission is granted at the project level because jobs are project-scoped resources, while data read access is granted on the dataset to limit exposure. This combination lets the service account run jobs that read the target dataset without granting rights over other datasets. It excludes dataset creation and deletion permissions, satisfying least privilege.
- ✗
Grant the service account the BigQuery Data Viewer role at the project level.
Why it's wrong here
BigQuery Data Viewer grants read access to data, but it does not include the permissions needed to run query jobs, such as bigquery.jobs.create. The service account would be able to read tables directly but unable to submit jobs. It also applies project-wide, which is broader than needed for a single dataset.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PDE question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PDE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PDE exam.