professional-cloud-data-engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A financial enterprise is designing a streaming ingestion pipeline to import sensitive customer transactions from an on-premises datacenter into a BigQuery data warehouse. The architecture must satisfy several strict security, encryption, and auditability requirements:
Which architecture and implementation strategy satisfies these requirements?
This architecture establishes an end-to-end secure, auditable, and compliant data ingestion architecture by combining client-side envelope encryption, Customer-Managed Encryption Keys (CMEK), short-lived credential management, and audit log enrichment across Google Cloud services.
roles/iam.serviceAccountTokenCreator) role generate short-lived OAuth 2.0 access tokens, mitigating credential leakage risks.X-Goog-Request-Reason HTTP header on API requests embeds the deployment run ID directly into Cloud Audit Logs, allowing teams to correlate deployment execution logs with infrastructure modifications.This solution fully satisfies all security constraints without architectural compromises. It leverages native Google Cloud services (Cloud KMS/HSM, BigQuery AEAD functions, Cloud IAM, and Cloud Logging) to minimize operational complexity while providing maximum security and auditability.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.