GCP Professional Cloud Security Engineer Practice Question
Your security team is creating an organization-level aggregated log sink that exports all Admin Activity and Data Access audit logs from every current and future project into a BigQuery dataset located in a central security project. The team must grant the sink's automatically-created service account the minimum predefined BigQuery IAM role that still allows the sink to create new tables and write log entries into the dataset, but nothing more. Which role should you assign to the service account on the destination dataset to meet these requirements?
BigQuery Data Editor (roles/bigquery.dataEditor) on the destination dataset
BigQuery Data Owner (roles/bigquery.dataOwner) on the destination dataset
BigQuery JobUser (roles/bigquery.jobUser) on the destination dataset
BigQuery User (roles/bigquery.user) on the destination dataset
When a Cloud Logging sink writes to BigQuery, its writer identity must be able to create new tables (if they do not yet exist) and insert rows into those tables. The least-privilege predefined role that provides exactly these capabilities on a dataset is BigQuery Data Editor (roles/bigquery.dataEditor). This role includes permissions such as bigquery.tables.create and bigquery.tables.updateData, which are required for the sink to function. Granting BigQuery Data Owner would also work but exceeds the minimum necessary privileges, while BigQuery User or BigQuery JobUser do not allow table creation or data insertion, so the export would fail.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the purpose of the BigQuery Data Editor role in this context?
Open an interactive chat with Bash
Why is the BigQuery Data Owner role not suitable for this scenario?
Open an interactive chat with Bash
What permissions does the BigQuery Data Editor role include, and why are they critical for the log sink operation?
Open an interactive chat with Bash
What does the BigQuery Data Editor role allow in terms of permissions?
Open an interactive chat with Bash
How does a Cloud Logging sink's writer identity interact with BigQuery?
Open an interactive chat with Bash
Why is roles/bigquery.dataEditor preferred over roles/bigquery.dataOwner in this scenario?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .