professional-cloud-data-engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise maintains a central data lakehouse architecture managed by Dataplex Universal Catalog, consisting of native BigQuery analytical tables and raw semi-structured data residing in Cloud Storage bucket assets. The compliance team requires an automated solution to:
Which configuration strategy should the data engineering team implement to meet these governance requirements?
Upgrade Cloud Storage bucket assets in Dataplex to BigLake tables, configure Sensitive Data Protection profiling to scan and classify columns, and enforce dynamic data masking using taxonomy-based policy tags in BigQuery.
Grant analysts the Dataplex Data Reader role at the lake level, create VPC Service Controls perimeters around Cloud Storage, and deploy Cloud DLP inspect job triggers that publish violation alerts to Pub/Sub.
Configure Dataplex Discovery with Dataproc Metastore to manage table schemas, and apply IAM conditions at the lake level using the Dataplex Metadata Reader role to hide sensitive column schema definitions.
Retain standard external tables for Cloud Storage bucket assets, run scheduled Dataflow pipelines calling the Sensitive Data Protection API to rewrite files with format-preserving encryption, and distribute Cloud KMS keys to authorized users.
Upgrade Cloud Storage bucket assets in Dataplex to BigLake tables, configure Sensitive Data Protection profiling to scan and classify columns, and enforce dynamic data masking using taxonomy-based policy tags in BigQuery.
Dataplex Universal Catalog works in tandem with Sensitive Data Protection (Cloud DLP) and BigLake to deliver unified, automated data discovery, classification, and security enforcement across heterogeneous cloud storage layers.
Standard BigQuery external tables do not support column-level security or dynamic data masking. Upgrading assets to BigLake tables brings first-class governance and masking capabilities to data lakes, unifying the security posture across all data lakehouse assets.
Grant analysts the Dataplex Data Reader role at the lake level, create VPC Service Controls perimeters around Cloud Storage, and deploy Cloud DLP inspect job triggers that publish violation alerts to Pub/Sub.
Configure Dataplex Discovery with Dataproc Metastore to manage table schemas, and apply IAM conditions at the lake level using the Dataplex Metadata Reader role to hide sensitive column schema definitions.
Retain standard external tables for Cloud Storage bucket assets, run scheduled Dataflow pipelines calling the Sensitive Data Protection API to rewrite files with format-preserving encryption, and distribute Cloud KMS keys to authorized users.