Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise is designing an automated data ingestion pipeline to process transaction records before storing them in BigQuery for analytics. The incoming records include sensitive commercial and personally identifiable information (PII) with the following specific requirements:
Which combination of Sensitive Data Protection (Cloud DLP) de-identification transformations should the cloud architect specify in the de-identification template?
Sensitive Data Protection (formerly Cloud DLP) provides configurable de-identification transformations that allow organizations to obfuscate, tokenize, mask, or generalize sensitive data at scale across streaming and batch pipelines.
infoTypeTransformations configuration inspects the text using built-in detectors (such as EMAIL_ADDRESS and PHONE_NUMBER) and applies character masking to replace matching tokens with characters like # or *.This architecture accurately satisfies all operational and structural constraints. It avoids breaking downstream schema constraints on legacy applications while maintaining strong de-identification and risk-mitigation standards across structured and unstructured data formats.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.