An App Engine service deployed with the default App Engine service account needs read access to a BigQuery dataset in another team's project you cannot access. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Ask the other team to grant your default App Engine service account the BigQuery Data Viewer role..
Why this is the answer
The correct approach is to ask the other team to grant your default App Engine service account the BigQuery Data Viewer role. This is because the BigQuery dataset resides in their project, so they control access to it. The BigQuery Data Viewer role provides read-only access to BigQuery datasets, which is appropriate for simply reading data. The BigQuery Job User role allows users to run jobs, including queries, but doesn't inherently grant data viewing permissions to specific datasets without additional roles; it's also a broader permission than necessary for read-only access. You cannot grant roles to a service account in another project from your own project's Cloud IAM; permissions are granted on the resource itself (the BigQuery dataset in the other project). Granting a service account from the other team roles in your project is irrelevant to your App Engine service account needing to read their data.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed