🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 52 minutes remaining!

GCP Associate Cloud Engineer Practice Question

Your company runs several projects within a single Cloud Organization. In one project, a developer needs to be able to list existing BigQuery datasets and update the datasets' labels, but must not create new tables or read any table data. None of the predefined BigQuery roles match these exact requirements. Which action best follows Google Cloud's principle of least privilege?

  • Grant the developer the predefined BigQuery Data Editor role; although it also allows creating tables, the extra permissions are acceptable.

  • Ask the developer to define a custom role in their personal Google Account and import that role into the project.

  • Create a project-level custom IAM role that includes only the required BigQuery permissions and grant it to the developer.

  • Define an organization-level custom role with the required permissions and rely on inheritance so the developer automatically receives it.

GCP Associate Cloud Engineer
Configuring access and security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot