GCP Professional Cloud Security Engineer Practice Question

Your organization stores employee records in a BigQuery table. All staff must be able to run existing queries on the table, but only members of the "hr-analysts" group should see the SSN and Salary columns. Other users must receive NULLs for those two columns without modifying any queries or creating additional views. Which approach meets the requirement while following Google-recommended practices for column-level security?

  • Apply a row-level security policy that filters out SSN and Salary for non-HR users.

  • Encrypt the SSN and Salary columns with a dedicated CMEK key and grant Cloud KMS access only to the hr-analysts group.

  • Create a Data Catalog taxonomy, assign policy tags to the SSN and Salary columns, and grant roles/datacatalog.categoryFineGrainedReader on those policy tags to the hr-analysts group only.

  • Build an authorized view that omits SSN and Salary, share that view with all users, and revoke access to the underlying table.

GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot