Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Google Professional Cloud Database Engineer Exam - Topic 10 Question 68 Discussion

An analytics team needs to read data out of Cloud SQL for SQL Server and update a table in Cloud Spanner. You need to create a service account and grant least privilege access using predefined roles. What roles should you assign to the service account?
A) roles/cloudsql.viewer and roles/spanner.databaseUser
B) roles/cloudsql.editor and roles/spanner.admin
C) roles/cloudsql.client and roles/spanner.databaseReader
D) roles/cloudsql.instanceUser and roles/spanner.databaseUser

Google Professional Cloud Database Engineer Exam - Topic 10 Question 68 Discussion

Actual exam question for Google's Professional Cloud Database Engineer exam
Question #: 68
Topic #: 10
[All Professional Cloud Database Engineer Questions]

An analytics team needs to read data out of Cloud SQL for SQL Server and update a table in Cloud Spanner. You need to create a service account and grant least privilege access using predefined roles. What roles should you assign to the service account?

Show Suggested Answer Hide Answer
Suggested Answer: A

To read data out of Cloud SQL for SQL Server, you need to use a service account with the roles/cloudsql.viewer role on the Cloud SQL instance. This role grants the service account permission to read data from the instance. Whereas roles/cloudsql.instanceUser will only allow to login to cloud SQL instance. No resource will be allowed to view.


Contribute your Thoughts:

0/2000 characters
Alishia
26 minutes ago
Option D could work too. Instance user is important for access.
upvoted 0 times
...
Shawnta
5 days ago
I agree, A makes sense. Viewer and database user roles fit well.
upvoted 0 times
...
Thurman
10 days ago
I think option A is the best. Least privilege is key.
upvoted 0 times
...
Allene
16 days ago
Wait, can you really use viewer access for Cloud SQL? Seems odd.
upvoted 0 times
...
Chandra
21 days ago
Definitely A), it’s the safest option!
upvoted 0 times
...
Denny
26 days ago
D) sounds right, but I’m not sure about the instanceUser role.
upvoted 0 times
...
Goldie
2 months ago
I think B) is too much access, not least privilege.
upvoted 0 times
...
Benedict
3 months ago
A) roles/cloudsql.viewer and roles/spanner.databaseUser is the way to go!
upvoted 0 times
...
Merilyn
3 months ago
I lean towards D because it seems to balance access well, but I’m not completely confident about the roles for Spanner.
upvoted 0 times
...
Erick
3 months ago
I'm not entirely sure, but I feel like roles/cloudsql.instanceUser might be necessary to connect to Cloud SQL.
upvoted 0 times
...
Minna
4 months ago
I remember practicing a similar question, and I think roles/cloudsql.viewer is definitely a safer option than editor.
upvoted 0 times
...
Carmela
4 months ago
I think the least privilege principle means we should avoid roles that give too much access, so maybe A or D?
upvoted 0 times
...

Save Cancel