🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 51 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

A health-insurance provider must copy several BigQuery tables containing the 10-digit numeric column member_id from its production project to a separate analytics project for data scientists. Compliance requires hiding the real identifiers, allowing analysts to perform equality joins on member_id, and enabling a small security team to recover the original values during fraud investigations without involving the analysts. Which Google Cloud Sensitive Data Protection configuration meets all requirements with the least operational overhead?

  • Mask every digit of member_id with the character "#" before exporting the tables.

  • Apply a date-shifting transformation to member_id and instruct analysts to cast the shifted value to STRING when joining.

  • Run an SDP inspection job that applies deterministic encryption with CryptoDeterministicConfig, writes the result as a surrogate infoType, and protects the key in Cloud KMS; grant only the security team dlp.jobs.reidentify and KMS decrypt permissions.

  • Encrypt member_id with format-preserving encryption (FFX) but do not store a surrogate infoType to prevent re-identification.

GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot