Courseiva

PDE Designing Data Processing Systems Practice Question

You need to allow a data analyst to run queries on a BigQuery dataset but prevent them from modifying the data or deleting the dataset. Which IAM role should you grant?

⚠ Common exam trap

The trap is picking roles/bigquery.jobUser alone because it 'lets you run queries,' but jobUser does not grant data access — you need dataViewer (or higher) on the dataset as well.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

roles/bigquery.dataViewer

roles/bigquery.dataViewer grants read-only access to BigQuery datasets, tables, and views, allowing the analyst to run queries and view metadata but not modify data or delete the dataset. It is the least-privilege role that satisfies the requirement of querying without write or delete permissions. This role is typically paired with roles/bigquery.jobUser at the project level so the user can actually run jobs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    roles/bigquery.dataOwner

    Why it's wrong here

    roles/bigquery.dataOwner grants full control of the dataset, including updating and deleting it, which directly violates the requirement to prevent modification and deletion. It is tempting because it certainly allows querying, and it would be correct for a dataset administrator who must manage the data.

  • ✓

    roles/bigquery.dataViewer

    Why this is correct

    roles/bigquery.dataViewer grants read access to datasets, tables and views, permitting queries while denying write operations such as inserts, updates, deletes or dataset removal. It therefore satisfies both constraints: the analyst can run queries but cannot modify data or delete the dataset.

  • ✗

    roles/bigquery.jobUser

    Why it's wrong here

    roles/bigquery.jobUser permits running jobs in a project but grants no dataset-level read access, so the analyst cannot query the data itself. It is tempting because it is the standard role for executing query jobs, and it would be correct when paired with a separate dataset-level read role.

  • ✗

    roles/bigquery.dataEditor

    Why it's wrong here

    roles/bigquery.dataEditor allows reading and querying but also permits modifying and deleting tables and the dataset, breaching the no-modification requirement. It is tempting because it covers query access, and it would be correct for a data engineer who must load and transform data.

About these practice questions

Courseiva writes every PDE question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PDE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PDE exam.