GCP Professional Cloud Security Engineer Practice Question

A healthcare provider exports multiple BigQuery tables from its production database to a separate analytics project. The tables contain patient identifiers such as medical record number (MRN) and government ID. Data scientists must be able to join the de-identified tables on these identifiers to build longitudinal views, but only a restricted compliance team may later reverse the process to reveal the original values if legally required. Which Sensitive Data Protection (Cloud DLP) transformation best meets these requirements?

  • Shift each identifier value by a random offset to hide the real data while keeping the format intact.

  • Redact the identifier fields so they are removed entirely from the exported tables.

  • Mask each identifier by replacing all but the last four characters with the "#" symbol.

  • Apply cryptographic deterministic encryption using a Cloud KMS-protected key (CryptoDeterministicConfig) to pseudonymize the identifiers.

GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot