GCP Professional Cloud Security Engineer Practice Question
Your company keeps all sales in one BigQuery table, sales.central_facts, which contains a region_code column. Analysts already belong to regional IAM groups such as emea-analysts@corp and apac-analysts@corp. Compliance requires each group to see only the rows for its region. You must meet these rules while keeping a single physical table and avoiding per-region views. What is the lowest-maintenance way to enforce the restriction?
Define row access policies on sales.central_facts that filter on region_code and grant each regional IAM group access to its policy.
Apply Data Catalog policy tags to the region_code column and assign tag-based roles to the regional analyst groups.
Partition sales.central_facts on region_code and rely on automatic partition pruning based on the user's identity.
Create an authorized view per region that filters by region_code and grant each IAM group access to its view.
Create BigQuery row access policies on sales.central_facts that filter rows with expressions like region_code = 'EMEA' and bind each policy to the corresponding IAM group. BigQuery automatically returns only rows matching a policy associated with the querying principal, and the policies are stored in the table's metadata, so no extra views or data copies are needed. Column policy tags constrain columns, not rows; table partitioning does not enforce security; multiple authorized views add operational overhead.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are BigQuery row access policies?
Open an interactive chat with Bash
How do IAM groups interact with row access policies?
Open an interactive chat with Bash
Why are authorized views higher maintenance compared to row access policies?
Open an interactive chat with Bash
What are BigQuery row access policies?
Open an interactive chat with Bash
How does IAM interact with row access policies in BigQuery?
Open an interactive chat with Bash
What are the advantages of row access policies over authorized views?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .