Controlling who can read a bucket, and what uniform access changes
Cloud Storage supports two access control systems: uniform bucket-level access, which relies solely on Cloud IAM policies applied consistently to all objects in a bucket, and fine-grained access, which combines IAM with legacy Access Control Lists (ACLs) that can be set per object or bucket. Choosing the right method affects how you manage public exposure, permission granularity, and compliance requirements for your data.
Must-know
- Uniform bucket-level access disables ACLs entirely, enforcing IAM permissions uniformly across all objects in the bucket, which simplifies auditing and is Google's recommended default for most workloads.
- Fine-grained access allows individual objects to have different permissions via ACLs (e.g., one object public, another private) even within the same bucket, but adds management complexity.
- Public access can be granted by assigning the allUsers or allAuthenticatedUsers identity IAM role (like Storage Object Viewer) at the bucket or object level, making data readable without authentication.
- Public Access Prevention (PAP) is an organization policy/bucket setting that blocks public access regardless of IAM or ACL grants, providing an extra safeguard against accidental exposure.
- Once uniform bucket-level access is enabled, it can be reverted to fine-grained only within 90 days; after that window the switch becomes permanent for that bucket.
- Signed URLs and signed policy documents offer a time-limited, credential-free way to grant temporary access to specific objects without changing bucket-level IAM or ACL settings.
A data practitioner manages a Cloud Storage bucket that stores analytics exports for several teams. The security team wants all access to the bucket to be governed exclusively through IAM policies, with no possibility of individual objects having different permissions set through access control lists (ACLs). Which setting should the practitioner configure on the bucket?
What you have tried across GCP ADP's objectives, not a readiness score.
Data Preparation and Ingestion
- When to load first and when to transform first, and what sits between the two
- Picking a way to move existing data into Google Cloud
- Judging whether a dataset is trustworthy enough to build on
- Fixing messy records before they reach a report
- Telling CSV, JSON, Parquet, Avro, and relational tables apart, and where each fits
- Picking how to pull data out of a source system
- Matching a workload to the right storage or database service
- Getting files and tables loaded with a CLI, a transfer service, or a client library
Data Analysis and Presentation
- Writing BigQuery SQL that answers a reporting question
- Exploring and charting data inside a hosted notebook
- Turning a question from the business into an analysis that settles it
- Building a dashboard and getting it in front of the right people
- Deciding whether a job calls for Looker or for Looker Studio
- Editing LookML to change what a model exposes
- Spotting a problem worth solving with BigQuery ML or AutoML
- Calling a hosted Google language model straight from BigQuery
- Sequencing a machine learning project from raw data to served predictions
- Building, fitting, and scoring a model with SQL alone
- Running predictions against a model you already trained
- Keeping trained models catalogued in one place
Data Pipeline Orchestration
- Matching a transformation job to Dataproc, Dataflow, Dataform, or a managed alternative
- Weighing whether the transform belongs before or after the load
- Assembling the services a simple transformation pipeline needs
- Putting a query on a schedule and keeping it running
- Watching a Dataflow job and spotting where it stalls
- Reading logs and metrics to work out what a pipeline actually did
- Choosing what should drive a multi-step workflow
- Streaming messages into BigQuery as they arrive rather than in batches
- Wiring a trigger so one event starts the next step
Data Management
- Granting only the access a person or service actually needs
- Controlling who can read a bucket, and what uniform access changes
- Sharing a dataset with another team or company without copying it
- Matching a storage class to how often the data gets read
- Expiring old data automatically so it stops costing money
- Picking somewhere to park data that must be kept but is rarely read
- Comparing the managed backup and restore options across services
- Working out when a second copy is worth what it costs
- Regions, dual-regions, multi-regions, and zones as redundancy choices
- Deciding who should hold the encryption keys
- What a key management service does for creating, rotating, and revoking keys
- Protecting data on the wire versus data sitting on a disk
Coverage checked against the published exam guide on Aug 12, 2026.
These are independent practice questions, written against this certification's published exam guide. They are not the certification vendor's own questions, and not the real exam.