professional-cloud-data-engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise data lake integrates Google Cloud Storage and BigQuery data assets governed by Dataplex. A data engineer needs to enforce row-level security on a centralized transactions table so regional analysts can only view data corresponding to their assigned region.
A junior administrator recommends granting the Filtered Data Viewer (roles/bigquery.filteredDataViewer) IAM role directly to the regional analyst user groups at the BigQuery dataset level, and then executing CREATE ROW ACCESS POLICY DDL statements for each region.
Why does this approach violate Google Cloud security best practices, and what is the correct implementation?
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.