GCP Professional Cloud Security Engineer Practice Question

While migrating 10 years of purchase data from Cloud SQL for MySQL to BigQuery, you must scrub a 16-digit credit_card_number column. Compliance requires that analysts can still join historical and new tables on the protected value, the field must remain exactly 16 numeric characters so existing regex-based ETL jobs keep working, and a restricted security team must be able to re-identify a card if fraud is reported. Which Sensitive Data Protection (DLP) de-identification technique best meets all these needs with minimal schema changes?

  • Redaction of the first 12 digits, leaving only the final 4 digits visible

  • Format-preserving encryption (FPE) using the numeric alphabet (FPE_FF31)

  • Tokenization that replaces each card number with a randomly generated surrogate key

  • Bucketing card numbers into predefined numeric ranges

GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot