professional-cloud-data-engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise is establishing a federated data governance model (data mesh) where autonomous domain teams build and deploy their own analytical data products across multiple Google Cloud projects. The central data platform team needs to implement a scalable, automated cross-system policy enforcement framework that:
Which architectural solution should the central data platform and governance team implement?
Deploy Security Health Analytics detectors and VPC Service Controls perimeters around each domain project while restricting access using BigQuery authorized views.
Consolidate all distributed domain datasets into a single monolithic BigQuery project and use Cloud KMS customer-managed encryption keys (CMEK) to isolate table access per domain.
Require each domain team to manually maintain local schema definition files, assign dataset-level IAM reader permissions, and configure custom cryptographic hashing functions inside domain ETL pipelines.
Define centralized Sensitive Data Protection inspection templates to automatically scan and classify distributed data, publish standardized Data Catalog policy taxonomies, and enforce IAM fine-grained reader roles on BigQuery column-level policy tags.
Deploy Security Health Analytics detectors and VPC Service Controls perimeters around each domain project while restricting access using BigQuery authorized views.
Consolidate all distributed domain datasets into a single monolithic BigQuery project and use Cloud KMS customer-managed encryption keys (CMEK) to isolate table access per domain.
Require each domain team to manually maintain local schema definition files, assign dataset-level IAM reader permissions, and configure custom cryptographic hashing functions inside domain ETL pipelines.
Define centralized Sensitive Data Protection inspection templates to automatically scan and classify distributed data, publish standardized Data Catalog policy taxonomies, and enforce IAM fine-grained reader roles on BigQuery column-level policy tags.
Centralized policy enforcement in a federated data governance model combines automated sensitive data discovery with standardized metadata taxonomies. The central governance team defines global Sensitive Data Protection (Cloud DLP) inspection templates and centrally managed Data Catalog policy taxonomies, while allowing distributed domain teams to own and operate their data product pipelines independently.
Fine-Grained Reader role via Cloud IAM can view unmasked sensitive attributes.This approach strikes the required balance in a data mesh architecture: it establishes central guardrails and automated compliance tooling without turning the central governance team into an operational bottleneck.