Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 302 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 302

Select 3Google Cloud Platform

You are a security engineer at a company that uses Google Cloud for its data storage and analytics needs. The organization has a BigQuery dataset containing sensitive customer data. Only members of the 'Data Analysts' group should have read access to the dataset, while members of the 'Data Engineers' group should have full control over it. Additionally, the dataset must not be publicly accessible. What steps should you take to enforce these access restrictions?

  1. A

    Grant the 'roles/bigquery.dataViewer' role to the 'Data Analysts' group at the dataset level.

  2. B

    Grant the 'roles/bigquery.admin' role to the 'Data Engineers' group at the dataset level.

  3. C

    Ensure the dataset’s IAM policy does not include 'allUsers' or 'allAuthenticatedUsers' as members.

  4. D

    Grant the 'roles/storage.objectViewer' role to the 'Data Analysts' group at the project level.

  5. E

    Enable VPC Service Controls to restrict access to the dataset.

Show answer and explanation

Correct answers: A, B, C

Explanation

To restrict access to BigQuery datasets, you should use IAM roles to define granular permissions for specific groups. In this case, 'roles/bigquery.dataViewer' provides read-only access for the 'Data Analysts' group, while 'roles/bigquery.admin' grants full control to the 'Data Engineers' group. Ensuring the dataset’s IAM policy does not include 'allUsers' or 'allAuthenticatedUsers' prevents public access. VPC Service Controls can be an additional layer of security, but they are not explicitly required in this scenario.

  • A. Correct.

    This grants read-only access to the BigQuery dataset for the 'Data Analysts' group, which aligns with the requirement.

  • B. Correct.

    This grants full control over the BigQuery dataset to the 'Data Engineers' group, which aligns with the requirement.

  • C. Correct.

    Including 'allUsers' or 'allAuthenticatedUsers' in the IAM policy would make the dataset publicly accessible, violating the requirement.

  • D. Incorrect.

    This role applies to Cloud Storage objects, not BigQuery datasets, so it is irrelevant to the scenario.

  • E. Incorrect.

    While VPC Service Controls can help restrict access in a broader sense, the scenario specifically focuses on IAM role assignments and public access restrictions.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam