VMs in the web-applications project need BigQuery dataset access in crm-databases-proj. Following best practices for cross-project service account access, what should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Grant bigquery.dataViewer on crm-databases-proj to the web-applications identities and grant required roles in web-applications..
Why this is the answer
The correct approach is to grant the bigquery.dataViewer role on the crm-databases-proj to the service account(s) or other identities associated with the VMs in the web-applications project. This follows the principle of least privilege, providing only the necessary BigQuery access in the target project. You would also ensure the VMs have the necessary roles within their own web-applications project to use their service accounts. Incorrect options are: Granting Project Owner roles is overly permissive and violates the principle of least privilege, giving broad control instead of specific BigQuery access. Granting bigquery.dataViewer on web-applications is irrelevant for accessing BigQuery data in crm-databases-proj.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed