Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise is architecting an end-to-end data governance and security pipeline for an AI/ML workload on Google Cloud. The architecture must satisfy three strict privacy and compliance requirements:
Which combination of Google Cloud security controls and architectural services meets all of these requirements?
Deploy VPC Service Controls perimeters around Cloud Storage to filter outbound PII; enforce BigQuery row-level security (RLS) policies for feature engineering; apply Binary Authorization image signing on Vertex AI containers.
Configure BigQuery dynamic data masking using policy tags on dataset schemas; utilize k-means clustering in BigQuery ML for feature anonymization; attach Customer-Managed Encryption Keys (CMEK) to Vertex AI Workbench persistent disks.
De-identify unstructured text using a Dataflow pipeline with Sensitive Data Protection (Cloud DLP) templates; apply BigQuery differential privacy aggregations during feature extraction; configure Vertex AI custom training jobs on compute instances with Confidential Computing enabled.
Use Dataplex auto-data quality scans to drop rows with sensitive metadata; execute standard SQL SHA256 hashing functions in BigQuery for feature engineering; configure Shielded VM Secure Boot on Vertex AI custom jobs.
Deploy VPC Service Controls perimeters around Cloud Storage to filter outbound PII; enforce BigQuery row-level security (RLS) policies for feature engineering; apply Binary Authorization image signing on Vertex AI containers.
Configure BigQuery dynamic data masking using policy tags on dataset schemas; utilize k-means clustering in BigQuery ML for feature anonymization; attach Customer-Managed Encryption Keys (CMEK) to Vertex AI Workbench persistent disks.
De-identify unstructured text using a Dataflow pipeline with Sensitive Data Protection (Cloud DLP) templates; apply BigQuery differential privacy aggregations during feature extraction; configure Vertex AI custom training jobs on compute instances with Confidential Computing enabled.
This architecture leverages Sensitive Data Protection (Cloud DLP), BigQuery differential privacy, and Vertex AI Confidential Computing to enforce end-to-end data governance, mathematical privacy guarantees, and hardware-level memory isolation across the entire machine learning lifecycle.
This combination aligns directly with standard AI governance and security frameworks by combining content-aware inspection, mathematical privacy bounds, and hardware-enforced trusted execution environments.
Use Dataplex auto-data quality scans to drop rows with sensitive metadata; execute standard SQL SHA256 hashing functions in BigQuery for feature engineering; configure Shielded VM Secure Boot on Vertex AI custom jobs.