Skip to content

Granting only the access a person or service actually needs

Least privileged access in Google Cloud IAM means granting only the specific permissions a principal needs to perform its job, using the narrowest role and resource scope possible. This is achieved by preferring predefined or custom roles over broad basic roles, granting access at the lowest necessary point in the resource hierarchy, and continuously auditing granted permissions against actual usage.

Must-know

  • Basic roles (Owner, Editor, Viewer) grant broad, project-wide permissions across all services and should be avoided in favor of predefined roles (e.g., BigQuery Data Viewer, Storage Object Viewer) that scope access to a single service and action set.
  • IAM policies are inherited down the resource hierarchy (organization > folder > project > resource), so granting a role at a higher level automatically applies it to all child resources. Bind roles at the lowest level that satisfies the need to avoid over-provisioning.
  • Custom roles let you bundle only the exact permissions required when no predefined role fits, but they require ongoing maintenance as Google Cloud APIs and permissions evolve.
  • Service accounts should be granted narrowly scoped roles for their specific workload and never the Owner/Editor basic role or the default compute service account's broad permissions in production.
  • IAM Conditions allow attribute-based, conditional grants (e.g., time-bound access or resource-name restrictions) to further tighten access beyond what a role alone provides.
  • Use Policy Analyzer and IAM Recommender to identify unused or excessive permissions granted to principals and right-size access over time, and prefer granting roles to groups rather than individual users for easier auditing and management.
Check this objectiveFree · always available

A data practitioner is configuring IAM permissions for a service account that runs a Dataflow pipeline. The pipeline only needs to read from one specific Cloud Storage bucket and write to one specific BigQuery table. No available predefined role matches this exact combination without granting excess access. According to least privileged access principles, what should the data practitioner do?

Your objective map0 tried · 0 right · 41 untouched

What you have tried across GCP ADP's objectives, not a readiness score.

Coverage checked against the published exam guide on Aug 12, 2026.

These are independent practice questions, written against this certification's published exam guide. They are not the certification vendor's own questions, and not the real exam.