PDE Designing Data Processing Systems Practice Question
You need to allow a data analyst to run queries on a BigQuery dataset but prevent them from modifying the data or deleting the dataset. Which IAM role should you grant?
⚠ Common exam trap
The trap is picking roles/bigquery.jobUser alone because it 'lets you run queries,' but jobUser does not grant data access — you need dataViewer (or higher) on the dataset as well.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
roles/bigquery.dataViewer
roles/bigquery.dataViewer grants read-only access to BigQuery datasets, tables, and views, allowing the analyst to run queries and view metadata but not modify data or delete the dataset. It is the least-privilege role that satisfies the requirement of querying without write or delete permissions. This role is typically paired with roles/bigquery.jobUser at the project level so the user can actually run jobs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
roles/bigquery.dataOwner
Why it's wrong here
roles/bigquery.dataOwner grants full control of the dataset, including updating and deleting it, which directly violates the requirement to prevent modification and deletion. It is tempting because it certainly allows querying, and it would be correct for a dataset administrator who must manage the data.
- ✓
roles/bigquery.dataViewer
Why this is correct
roles/bigquery.dataViewer grants read access to datasets, tables and views, permitting queries while denying write operations such as inserts, updates, deletes or dataset removal. It therefore satisfies both constraints: the analyst can run queries but cannot modify data or delete the dataset.
- ✗
roles/bigquery.jobUser
Why it's wrong here
roles/bigquery.jobUser permits running jobs in a project but grants no dataset-level read access, so the analyst cannot query the data itself. It is tempting because it is the standard role for executing query jobs, and it would be correct when paired with a separate dataset-level read role.
- ✗
roles/bigquery.dataEditor
Why it's wrong here
roles/bigquery.dataEditor allows reading and querying but also permits modifying and deleting tables and the dataset, breaching the no-modification requirement. It is tempting because it covers query access, and it would be correct for a data engineer who must load and transform data.
About these practice questions
Courseiva writes every PDE question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PDE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PDE exam.