professional-cloud-data-engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise data engineering team is configuring a centralized Data Studio (Looker Studio) reporting dashboard connected to BigQuery. The dashboard will be shared with both internal business analysts who have report edit permissions and external stakeholders who have view-only access.
The solution must satisfy the following governance and operational requirements:
Which configuration should the data engineering team implement?
Create reusable data sources using Service Account credentials to connect to BigQuery, and disable downloading, printing, and copying in the report's advanced sharing settings.
Create embedded data sources using Service Account credentials, and configure BigQuery authorized views while relying on default viewer sharing permissions.
Create reusable data sources using Viewer's credentials to connect to BigQuery, and grant external stakeholders individual IAM BigQuery Data Viewer roles.
Create embedded data sources using Owner's credentials to connect to BigQuery, and enforce organization-wide restricted sharing via Google Workspace admin policies.
Create reusable data sources using Service Account credentials to connect to BigQuery, and disable downloading, printing, and copying in the report's advanced sharing settings.
In Data Studio (Looker Studio), managing enterprise reporting at scale requires separating report layout editing from underlying data connection management, ensuring credential persistence, and restricting data dissemination. Creating a reusable data source that authenticates using a dedicated Google Cloud Service Account satisfies these requirements seamlessly.
Owner's Credentials). If the report creator departs the organization, scheduled refreshes and report queries continue uninterrupted.roles/bigquery.dataViewer and roles/bigquery.jobUser), eliminating the need to grant individual GCP IAM access to external viewers.This architecture establishes strict enterprise governance: reusable data sources lock down connection definitions, service accounts eliminate personal credential fragility, and advanced sharing settings prevent unauthorized data dissemination.
Create embedded data sources using Service Account credentials, and configure BigQuery authorized views while relying on default viewer sharing permissions.
Create reusable data sources using Viewer's credentials to connect to BigQuery, and grant external stakeholders individual IAM BigQuery Data Viewer roles.
Create embedded data sources using Owner's credentials to connect to BigQuery, and enforce organization-wide restricted sharing via Google Workspace admin policies.