Unlock the power of your data in the cloud! Get hands-on with Google Cloud's core data services like BigQuery and Looker to validate your practical skills in data ingestion, analysis, and management, and earn your Associate Data Practitioner certification!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A data engineering team is creating several new Google Cloud Storage buckets to store sensitive customer transaction records. To comply with internal security policies, the team must ensure that permissions are managed consistently across all objects in a bucket using only Cloud Identity and Access Management (Cloud IAM) policies, while completely disabling individual object-level Access Control Lists (ACLs).
Which Cloud Storage access control configuration should the team implement?
Uniform Bucket-Level Access (also known as uniform access) is a Google Cloud Storage security feature that unifies and simplifies access management. When enabled on a bucket, it completely disables object-level Access Control Lists (ACLs) and enforces access exclusively through Cloud Identity and Access Management (Cloud IAM) roles at the bucket, folder, or project level.
roles/storage.objectViewer or roles/storage.objectAdmin).storage.uniformBucketLevelAccess policy constraint.Uniform Bucket-Level Access is the Google Cloud recommended best practice for securing data storage. Compared to fine-grained ACLs, it guarantees that no object within a bucket can have separate, accidental public or unauthorized permissions attached to it.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.