Courseiva
hardMultiple Choice

PDE Practice Question: Refer to the exhibit

Exhibit

Refer to the exhibit.

```json
{
  "bindings": [
    {
      "role": "roles/bigquery.dataViewer",
      "members": [
        "group:analysts@example.com"
      ]
    }
  ]
}
```

Refer to the exhibit. A BigQuery dataset is shared with the group 'analysts@example.com' using the IAM policy shown. A user who is a member of this group reports that they cannot run queries on the dataset, though they can see the tables. What is the most likely reason?

⚠ Common exam trap

This question tests the distinction between dataset-level and project-level roles in BigQuery. Candidates often incorrectly assume that dataset-level view permissions are sufficient to run queries, but query jobs require the 'roles/bigquery.jobUser' role at the project level.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The group needs the 'roles/bigquery.jobUser' role at the project level.

The IAM policy grants the 'roles/bigquery.dataViewer' role at the dataset level, which allows the user to see tables but not run queries. To run queries, the user also needs the 'roles/bigquery.jobUser' role at the project level, because BigQuery query jobs are project-scoped resources. Without this role, the user lacks permission to create query jobs, even though they can view dataset metadata.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The group needs the 'roles/bigquery.jobUser' role at the project level.

    Why this is correct

    BigQuery separates metadata visibility from query execution: dataset-level roles such as `roles/bigquery.dataViewer` let the user list tables, but running jobs requires `roles/bigquery.jobUser` granted at the project level. Because the group only holds dataset-scoped access, the user can see tables yet cannot execute queries, satisfying the stem's constraint.

  • ✗

    The user is using an incorrect client library version.

    Why it's wrong here

    A client library version affects how requests are constructed, not whether the identity holds bigquery.dataViewer versus bigquery.user; the user can already list tables, so connectivity works. Library upgrades matter when an API method or authentication flow is unsupported by an outdated release.

  • ✗

    The user's account is not activated in the group membership.

    Why it's wrong here

    Group membership is evaluated from the directory, not activated per user; an unactivated membership would also prevent the table visibility the user already has. Deactivated accounts are the right diagnosis when a user cannot authenticate or appears absent from group-based access entirely.

  • ✗

    The dataset has an organization policy that denies query access.

    Why it's wrong here

    An organisation policy denying query access would also block the table listing the user currently sees, so it cannot explain visibility without query rights. Such policies are correct when you must restrict access by resource hierarchy regardless of IAM, for example enforcing domain-restricted sharing.

About these practice questions

Courseiva writes every PDE question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PDE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PDE exam.