professional-cloud-data-engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise is centralizing sensitive customer transaction data from multiple business units into a shared BigQuery data warehouse. The data engineering and security teams must implement a robust security architecture that satisfies the following requirements:
Which combination of Google Cloud security mechanisms should the team implement?
This architecture combines VPC Service Controls, BigQuery Row-Level Security (RLS), and BigQuery Column-Level Security using Policy Tags and Dynamic Data Masking to establish end-to-end context-aware security and fine-grained data access.
WHERE region = 'APAC') directly to the base table based on user group membership (GRANT TO), avoiding the operational maintenance and scaling limits of creating separate tables or hundreds of authorized views.roles/datacatalog.categoryFineGrainedReader) role can view unmasked cleartext values.This approach aligns with Google Cloud security best practices by enforcing the principle of least privilege, zero-trust network boundaries, and scalable fine-grained access controls without administrative overhead.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.