professional-cloud-data-engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
Your organization uses a custom on-premises visualization tool to generate business intelligence reports. The tool currently connects to relational databases using standard SQL protocols and does not natively support the BigQuery API.
You need to integrate this tool with BigQuery to analyze large datasets. Security policies mandate that the connection must not traverse the public internet, and BigQuery resources must be protected from data exfiltration by restricting access strictly to your hybrid network environment.
How should you securely integrate the on-premises tool with BigQuery?
Install the BigQuery JDBC or ODBC drivers on the on-premises server. Route traffic through Cloud VPN or Cloud Interconnect and enable Private Google Access to access BigQuery without using public IPs. Configure a VPC Service Controls perimeter around the BigQuery resources.
Install the BigQuery JDBC or ODBC drivers on the on-premises server. Configure VPC Network Peering to route traffic from the on-premises network directly to BigQuery. Secure the connection using Identity-Aware Proxy (IAP).
Export the BigQuery data to an on-premises database using the BigQuery Data Transfer Service over Cloud VPN. Connect the visualization tool to the local database to avoid public internet exposure.
Modify the custom tool to integrate directly with the BigQuery API. Route traffic over the public internet and use Google Cloud Armor to restrict access to the on-premises network's public IP range.
Install the BigQuery JDBC or ODBC drivers on the on-premises server. Route traffic through Cloud VPN or Cloud Interconnect and enable Private Google Access to access BigQuery without using public IPs. Configure a VPC Service Controls perimeter around the BigQuery resources.
The Simba JDBC and ODBC drivers for BigQuery allow legacy or custom applications that rely on standard SQL protocols to connect to BigQuery without requiring native API integration. Private Google Access (or Private Service Connect) allows on-premises networks connected via Cloud VPN or Cloud Interconnect to reach Google APIs using internal IP addresses. VPC Service Controls creates a secure perimeter around Google Cloud resources to mitigate data exfiltration risks.
This architecture seamlessly integrates legacy BI tools with modern cloud data warehouses while adhering to strict zero-trust and private networking mandates. It leverages purpose-built drivers for application compatibility and native Google Cloud networking security controls to ensure end-to-end protection.
Install the BigQuery JDBC or ODBC drivers on the on-premises server. Configure VPC Network Peering to route traffic from the on-premises network directly to BigQuery. Secure the connection using Identity-Aware Proxy (IAP).
Export the BigQuery data to an on-premises database using the BigQuery Data Transfer Service over Cloud VPN. Connect the visualization tool to the local database to avoid public internet exposure.
Modify the custom tool to integrate directly with the BigQuery API. Route traffic over the public internet and use Google Cloud Armor to restrict access to the on-premises network's public IP range.