professional-cloud-data-engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise is centralizing sensitive customer transaction data from multiple business units into a shared BigQuery data warehouse. The data engineering and security teams must implement a robust security architecture that satisfies the following requirements:
Which combination of Google Cloud security mechanisms should the team implement?
Establish IAM Conditions restricting dataset access based on request IP attributes, export partitioned data extracts to region-specific Cloud Storage buckets, and use Sensitive Data Protection to delete sensitive columns.
Configure VPC firewall egress rules targeting BigQuery endpoints, create materialized subset tables clustered by region, and apply client-side AEAD encryption to sensitive columns.
Enclose the BigQuery storage and compute projects within VPC Service Controls perimeters, define BigQuery Row-Level Security policies filtered by region, and implement policy tags with dynamic data masking and the Fine-Grained Reader role.
Deploy Private Google Access with Cloud Armor security policies, generate authorized views for each geographic region, and encrypt the entire dataset with Customer-Managed Encryption Keys (CMEK).
Establish IAM Conditions restricting dataset access based on request IP attributes, export partitioned data extracts to region-specific Cloud Storage buckets, and use Sensitive Data Protection to delete sensitive columns.
Configure VPC firewall egress rules targeting BigQuery endpoints, create materialized subset tables clustered by region, and apply client-side AEAD encryption to sensitive columns.
Enclose the BigQuery storage and compute projects within VPC Service Controls perimeters, define BigQuery Row-Level Security policies filtered by region, and implement policy tags with dynamic data masking and the Fine-Grained Reader role.
This architecture combines VPC Service Controls, BigQuery Row-Level Security (RLS), and BigQuery Column-Level Security using Policy Tags and Dynamic Data Masking to establish end-to-end context-aware security and fine-grained data access.
WHERE region = 'APAC') directly to the base table based on user group membership (GRANT TO), avoiding the operational maintenance and scaling limits of creating separate tables or hundreds of authorized views.roles/datacatalog.categoryFineGrainedReader) role can view unmasked cleartext values.This approach aligns with Google Cloud security best practices by enforcing the principle of least privilege, zero-trust network boundaries, and scalable fine-grained access controls without administrative overhead.
Deploy Private Google Access with Cloud Armor security policies, generate authorized views for each geographic region, and encrypt the entire dataset with Customer-Managed Encryption Keys (CMEK).