🔥 40% Off Crucial Exams Memberships — Deal ends today!

2 hours, 31 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your organization runs a multi-tenant application on Cloud SQL for PostgreSQL. A group of data scientists needs read-only access to the tables that reside in the "analytics" schema, but they must not be able to modify data or view objects in other schemas. The security team insists that access be enforced entirely inside the database engine, without relying on Cloud IAM or network controls. Which approach satisfies these requirements with the least operational overhead?

  • Enable IAM database authentication and grant the group the cloudsql.connectionViewer role so that login attempts are authenticated by IAM.

  • Assign the Cloud SQL Viewer IAM role to the data-scientists' Google groups at the project level to ensure they cannot modify data.

  • Add the data-scientists' office IP range to the instance's Authorized Networks list and leave database permissions unchanged.

  • Create a PostgreSQL role, grant it USAGE on the "analytics" schema and SELECT on all tables within that schema, then assign that role to each data-scientist user.

GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot