professional-cloud-data-engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
Your organization stores customer transaction data in a centralized BigQuery table named sales.transactions. You need to securely share this table with three distinct user groups while enforcing the principle of least privilege:
region = 'EMEA', and payment identifiers must be masked.How should you configure access controls and data policies in Google Cloud to achieve these requirements?
Use Sensitive Data Protection (Cloud DLP) to tokenize the entire table before loading it into BigQuery, store the cryptographic keys in Cloud KMS, and grant Cloud KMS CryptoKey Decrypter permissions only to the Finance Auditors.
Create separate authorized logical views for each user group in dedicated datasets, embedding custom SHA-256 SQL masking expressions and WHERE clauses, and grant table-level BigQuery Data Viewer permissions on each view.
Create a Data Catalog taxonomy with policy tags attached to the sensitive column. Grant Finance Auditors the Data Catalog Fine-Grained Reader role on the tag, attach a dynamic data policy with a masking rule to the tag and grant the BigQuery Masked Reader role to Business Analysts and Regional Sales Managers, and create a Row Access Policy on the table filtering on region for Regional Sales Managers.
Assign the BigQuery Admin role to Finance Auditors, create an authorized materialized view for Business Analysts with masked columns, and configure IAM Conditions on table-level access for Regional Sales Managers.
Use Sensitive Data Protection (Cloud DLP) to tokenize the entire table before loading it into BigQuery, store the cryptographic keys in Cloud KMS, and grant Cloud KMS CryptoKey Decrypter permissions only to the Finance Auditors.
Create separate authorized logical views for each user group in dedicated datasets, embedding custom SHA-256 SQL masking expressions and WHERE clauses, and grant table-level BigQuery Data Viewer permissions on each view.
Create a Data Catalog taxonomy with policy tags attached to the sensitive column. Grant Finance Auditors the Data Catalog Fine-Grained Reader role on the tag, attach a dynamic data policy with a masking rule to the tag and grant the BigQuery Masked Reader role to Business Analysts and Regional Sales Managers, and create a Row Access Policy on the table filtering on region for Regional Sales Managers.
This solution combines BigQuery Column-Level Access Control, Dynamic Data Masking (DDM) via Data Catalog policy tags, and Row-Level Security (RLS) to enforce multi-layered, fine-grained access controls.
roles/datacatalog.categoryFineGrainedReader) role on the taxonomy policy tag allows auditors to read the unmasked cleartext data in the tagged column across all rows.roles/bigquery.maskedReader) role allows their queries to execute normally while dynamically returning obscured/masked values.CREATE ROW ACCESS POLICY ... FILTER USING (region = 'EMEA')) restricts the returned rows to EMEA, while the assigned BigQuery Masked Reader role ensures that the payment identifier column in those permitted rows remains masked.This approach avoids data duplication, eliminates maintenance overhead associated with managing separate localized views or export tables, and natively enforces fine-grained authorization using standard Google Cloud IAM and BigQuery DDL policies.
Assign the BigQuery Admin role to Finance Auditors, create an authorized materialized view for Business Analysts with masked columns, and configure IAM Conditions on table-level access for Regional Sales Managers.