professional-cloud-data-engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise data architect is designing an automated de-identification pipeline using Sensitive Data Protection before ingesting a sensitive dataset into BigQuery. The source dataset contains four key fields with distinct compliance, system, and analytical constraints:
account_number: A fixed 10-digit numeric string that must be ingested by a legacy downstream application requiring strict 10-digit numeric format preservation, while also supporting two-way re-identification by security administrators.user_id: A customer identifier required for multi-table analytical joins across historical datasets; it requires two-way re-identification and maximum cryptographic security without character set or length preservation constraints.user_age: A quasi-identifier that must be generalized into discrete intervals (such as 20–29, 30–39) to reduce re-identification risk under k-anonymity requirements while retaining demographic utility.user_pin: A 4-digit secret that must never be reversible under any circumstances, but must maintain referential integrity across analytical queries.Which combination of Sensitive Data Protection transformational methods should the architect select for each respective column?
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.