hardMultiple Choice
PDE Practice Question: Refer to the exhibit
Exhibit
Refer to the exhibit.
```json
{
"bindings": [
{
"role": "roles/bigquery.dataViewer",
"members": [
"group:analysts@example.com"
]
}
]
}
```Refer to the exhibit. A BigQuery dataset is shared with the group 'analysts@example.com' using the IAM policy shown. A user who is a member of this group reports that they cannot run queries on the dataset, though they can see the tables. What is the most likely reason?
⚠ Common exam trap
This question tests the distinction between dataset-level and project-level roles in BigQuery. Candidates often incorrectly assume that dataset-level view permissions are sufficient to run queries, but query jobs require the 'roles/bigquery.jobUser' role at the project level.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The group needs the 'roles/bigquery.jobUser' role at the project level.
The IAM policy grants the 'roles/bigquery.dataViewer' role at the dataset level, which allows the user to see tables but not run queries. To run queries, the user also needs the 'roles/bigquery.jobUser' role at the project level, because BigQuery query jobs are project-scoped resources. Without this role, the user lacks permission to create query jobs, even though they can view dataset metadata.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The group needs the 'roles/bigquery.jobUser' role at the project level.
Why this is correct
BigQuery separates metadata visibility from query execution: dataset-level roles such as `roles/bigquery.dataViewer` let the user list tables, but running jobs requires `roles/bigquery.jobUser` granted at the project level. Because the group only holds dataset-scoped access, the user can see tables yet cannot execute queries, satisfying the stem's constraint.
- ✗
The user is using an incorrect client library version.
Why it's wrong here
A client library version affects how requests are constructed, not whether the identity holds bigquery.dataViewer versus bigquery.user; the user can already list tables, so connectivity works. Library upgrades matter when an API method or authentication flow is unsupported by an outdated release.
- ✗
The user's account is not activated in the group membership.
Why it's wrong here
Group membership is evaluated from the directory, not activated per user; an unactivated membership would also prevent the table visibility the user already has. Deactivated accounts are the right diagnosis when a user cannot authenticate or appears absent from group-based access entirely.
- ✗
The dataset has an organization policy that denies query access.
Why it's wrong here
An organisation policy denying query access would also block the table listing the user currently sees, so it cannot explain visibility without query rights. Such policies are correct when you must restrict access by resource hierarchy regardless of IAM, for example enforcing domain-restricted sharing.
About these practice questions
Courseiva writes every PDE question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PDE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PDE exam.