professional-cloud-data-engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A multinational financial services enterprise wants to share curated market analytics datasets with external corporate partners using BigQuery sharing (Analytics Hub).
The enterprise has established the following technical and governance requirements:
How should the data engineer configure the Analytics Hub environment?
Create a private data exchange, enable Public Discoverability on the listing, and deploy Datastream to capture and replicate subscriber query logs into a centralized security audit table.
Create the listing in a private data exchange, enable Public Discoverability by granting the Analytics Hub Viewer role (roles/analyticshub.viewer) to allAuthenticatedUsers, and enable the Subscriber Email Logging option during listing creation.
Create a publicly discoverable data exchange, configure individual listings as private, and enable Cloud Audit Logs Data Read logging on the publisher BigQuery dataset.
Create a private data exchange, keep the listings private, grant the BigQuery Data Viewer role directly to allAuthenticatedUsers on the source dataset, and configure VPC Service Controls egress rules.
Create a private data exchange, enable Public Discoverability on the listing, and deploy Datastream to capture and replicate subscriber query logs into a centralized security audit table.
Create the listing in a private data exchange, enable Public Discoverability by granting the Analytics Hub Viewer role (roles/analyticshub.viewer) to allAuthenticatedUsers, and enable the Subscriber Email Logging option during listing creation.
BigQuery Analytics Hub allows organizations to publish and subscribe to shared datasets across organization and project boundaries without data replication. An Analytics Hub listing packages a shared dataset and exposes it via a data exchange, enabling subscribers to provision read-only linked datasets.
roles/analyticshub.viewer to allAuthenticatedUsers, the enterprise keeps the broader exchange secured while making individual listings discoverable to authenticated Google Cloud accounts.job_principal_subject field of the INFORMATION_SCHEMA.SHARED_DATASET_USAGE view.INFORMATION_SCHEMA views.This solution leverages native Analytics Hub discovery permissions and built-in subscriber logging without requiring custom log ingestion pipelines or compromising the privacy of the primary data exchange.
Create a publicly discoverable data exchange, configure individual listings as private, and enable Cloud Audit Logs Data Read logging on the publisher BigQuery dataset.
Create a private data exchange, keep the listings private, grant the BigQuery Data Viewer role directly to allAuthenticatedUsers on the source dataset, and configure VPC Service Controls egress rules.