Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A security engineer is configuring Google Cloud Sensitive Data Protection (SDP) to inspect customer support logs stored across Cloud Storage buckets and BigQuery datasets. Preliminary inspection scans produced excessive false positives for custom customer account numbers because internal system transaction IDs share the same 9-digit format. In addition, the organization needs to detect employee identifiers across text files against an authoritative corporate roster of 600,000 employee IDs without causing memory or performance bottlenecks.
Which configuration should the security engineer implement in the SDP inspection template?
Define a custom regex infoType paired with hotword rules that raise match likelihood based on surrounding proximity terms, and create a stored infoType backed by BigQuery for the employee roster.
Configure Dataplex Universal Catalog discovery with semi-structured schema inference, and apply glob exclude patterns to ignore Cloud Storage log files containing 9-digit numbers.
Enable Storage Insights dataset generation for bucket metadata and run BigQuery SQL queries to filter securityInsights and object encryption fields.
Define a custom regular expression infoType with minLikelihood set to LIKELIHOOD_UNSPECIFIED, and embed the 600,000 employee IDs directly into an inline dictionary infoType.
Define a custom regex infoType paired with hotword rules that raise match likelihood based on surrounding proximity terms, and create a stored infoType backed by BigQuery for the employee roster.
Sensitive Data Protection (SDP) provides advanced inspection controls, including custom infoTypes, hotword rules, and stored infoTypes (such as large custom dictionaries). These mechanisms allow organizations to tune sensitivity detection, reduce false positives, and efficiently match structured data against massive enterprise datasets.
account, customer_id, or acct_no within a specific token window), SDP only promotes matches to LIKELY or VERY_LIKELY when contextual tokens are present nearby.Likelihood).Using hotword rules directly addresses format overlap between transaction IDs and account numbers, while leveraging stored infoTypes represents the architectural best practice for high-scale enterprise dictionary lookups in SDP.
Configure Dataplex Universal Catalog discovery with semi-structured schema inference, and apply glob exclude patterns to ignore Cloud Storage log files containing 9-digit numbers.
Enable Storage Insights dataset generation for bucket metadata and run BigQuery SQL queries to filter securityInsights and object encryption fields.
Define a custom regular expression infoType with minLikelihood set to LIKELIHOOD_UNSPECIFIED, and embed the 600,000 employee IDs directly into an inline dictionary infoType.