Granting only the access a person or service actually needs
Least privileged access in Google Cloud IAM means granting only the specific permissions a principal needs to perform its job, using the narrowest role and resource scope possible. This is achieved by preferring predefined or custom roles over broad basic roles, granting access at the lowest necessary point in the resource hierarchy, and continuously auditing granted permissions against actual usage.
Must-know
- Basic roles (Owner, Editor, Viewer) grant broad, project-wide permissions across all services and should be avoided in favor of predefined roles (e.g., BigQuery Data Viewer, Storage Object Viewer) that scope access to a single service and action set.
- IAM policies are inherited down the resource hierarchy (organization > folder > project > resource), so granting a role at a higher level automatically applies it to all child resources. Bind roles at the lowest level that satisfies the need to avoid over-provisioning.
- Custom roles let you bundle only the exact permissions required when no predefined role fits, but they require ongoing maintenance as Google Cloud APIs and permissions evolve.
- Service accounts should be granted narrowly scoped roles for their specific workload and never the Owner/Editor basic role or the default compute service account's broad permissions in production.
- IAM Conditions allow attribute-based, conditional grants (e.g., time-bound access or resource-name restrictions) to further tighten access beyond what a role alone provides.
- Use Policy Analyzer and IAM Recommender to identify unused or excessive permissions granted to principals and right-size access over time, and prefer granting roles to groups rather than individual users for easier auditing and management.
A data practitioner is configuring IAM permissions for a service account that runs a Dataflow pipeline. The pipeline only needs to read from one specific Cloud Storage bucket and write to one specific BigQuery table. No available predefined role matches this exact combination without granting excess access. According to least privileged access principles, what should the data practitioner do?
What you have tried across GCP ADP's objectives, not a readiness score.
Data Preparation and Ingestion
- When to load first and when to transform first, and what sits between the two
- Picking a way to move existing data into Google Cloud
- Judging whether a dataset is trustworthy enough to build on
- Fixing messy records before they reach a report
- Telling CSV, JSON, Parquet, Avro, and relational tables apart, and where each fits
- Picking how to pull data out of a source system
- Matching a workload to the right storage or database service
- Getting files and tables loaded with a CLI, a transfer service, or a client library
Data Analysis and Presentation
- Writing BigQuery SQL that answers a reporting question
- Exploring and charting data inside a hosted notebook
- Turning a question from the business into an analysis that settles it
- Building a dashboard and getting it in front of the right people
- Deciding whether a job calls for Looker or for Looker Studio
- Editing LookML to change what a model exposes
- Spotting a problem worth solving with BigQuery ML or AutoML
- Calling a hosted Google language model straight from BigQuery
- Sequencing a machine learning project from raw data to served predictions
- Building, fitting, and scoring a model with SQL alone
- Running predictions against a model you already trained
- Keeping trained models catalogued in one place
Data Pipeline Orchestration
- Matching a transformation job to Dataproc, Dataflow, Dataform, or a managed alternative
- Weighing whether the transform belongs before or after the load
- Assembling the services a simple transformation pipeline needs
- Putting a query on a schedule and keeping it running
- Watching a Dataflow job and spotting where it stalls
- Reading logs and metrics to work out what a pipeline actually did
- Choosing what should drive a multi-step workflow
- Streaming messages into BigQuery as they arrive rather than in batches
- Wiring a trigger so one event starts the next step
Data Management
- Granting only the access a person or service actually needs
- Controlling who can read a bucket, and what uniform access changes
- Sharing a dataset with another team or company without copying it
- Matching a storage class to how often the data gets read
- Expiring old data automatically so it stops costing money
- Picking somewhere to park data that must be kept but is rarely read
- Comparing the managed backup and restore options across services
- Working out when a second copy is worth what it costs
- Regions, dual-regions, multi-regions, and zones as redundancy choices
- Deciding who should hold the encryption keys
- What a key management service does for creating, rotating, and revoking keys
- Protecting data on the wire versus data sitting on a disk
Coverage checked against the published exam guide on Aug 12, 2026.
These are independent practice questions, written against this certification's published exam guide. They are not the certification vendor's own questions, and not the real exam.