In a regulated environment you must enforce least privilege in BigQuery. Which three approaches help achieve this?
Choose an answer
Tap an option to check your answer.
Correct answer: Restrict access to tables by role., Restrict BigQuery API access to approved users., Segregate data across multiple tables or databases..
Why this is the answer
Restricting access to tables by role (IAM roles) directly enforces least privilege by granting users only the permissions necessary for their job functions, such as read-only access for analysts or write access for data engineers. Restricting BigQuery API access to approved users ensures that only authorized individuals or services can interact with BigQuery resources, preventing unauthorized data access or manipulation. Segregating data across multiple tables or databases allows for finer-grained access control, where different datasets can have distinct access policies, further limiting exposure. Disabling writes to certain tables is a specific control, but not a general approach to least privilege. Encrypting data is a security best practice but doesn't directly enforce least privilege, which is about access control. Stackdriver Audit Logging is for monitoring compliance, not for enforcing it.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed