professional-cloud-data-engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise financial organization is designing an ingestion pipeline to integrate continuous, high-volume transactional logs from an on-premises database into a secured BigQuery data warehouse.
The technical, analytical, and compliance requirements are as follows:
Which ingestion and security design should the data engineering team implement?
This architecture combines high-throughput private network connectivity with client-side envelope encryption and native BigQuery column-level security to establish an end-to-end secured data ingestion and analytics pipeline.
AEAD.DECRYPT_STRING) at query runtime. Applying policy tags with dynamic data masking ensures unauthorized general analysts only see masked values, while fraud analysts with the Fine-Grained Reader (roles/datacatalog.categoryFineGrainedReader) role can access unmasked data and invoke AEAD decryption functions.This pattern aligns with the Google Cloud Secured Data Warehouse blueprint for external data sources, addressing throughput, client-side compliance, and granular role-based SQL access controls.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.