Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A security engineer is configuring Google Cloud Sensitive Data Protection (SDP) to inspect customer support logs stored across Cloud Storage buckets and BigQuery datasets. Preliminary inspection scans produced excessive false positives for custom customer account numbers because internal system transaction IDs share the same 9-digit format. In addition, the organization needs to detect employee identifiers across text files against an authoritative corporate roster of 600,000 employee IDs without causing memory or performance bottlenecks.
Which configuration should the security engineer implement in the SDP inspection template?
Sensitive Data Protection (SDP) provides advanced inspection controls, including custom infoTypes, hotword rules, and stored infoTypes (such as large custom dictionaries). These mechanisms allow organizations to tune sensitivity detection, reduce false positives, and efficiently match structured data against massive enterprise datasets.
account, customer_id, or acct_no within a specific token window), SDP only promotes matches to LIKELY or VERY_LIKELY when contextual tokens are present nearby.Likelihood).Using hotword rules directly addresses format overlap between transaction IDs and account numbers, while leveraging stored infoTypes represents the architectural best practice for high-scale enterprise dictionary lookups in SDP.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.