A Dataflow pipeline must deploy into a Shared VPC network and subnet provided by networking. Which IAM role do you grant, and to which principal, to enable pipeline workers to use the Shared VPC?
Choose an answer
Tap an option to check your answer.
Correct answer: Grant the compute.networkUser role to the service account that executes the Dataflow pipeline..
Why this is the answer
The compute.networkUser role allows a principal to use shared VPC networks. Dataflow workers, which are Compute Engine instances, need this permission to operate within the Shared VPC. The Dataflow pipeline's service account is the identity under which these worker instances run, making it the correct principal to receive this role. Granting it to the Dataflow service agent (a Google-managed service account) is incorrect because the service agent manages the Dataflow service itself, not the permissions for individual pipeline execution within user-defined networks. The dataflow.admin role is for managing Dataflow jobs, not for network access.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed