GCP Professional Cloud Security Engineer Practice Question

Your security operations team must continuously locate and classify credit-card and national-ID data that may appear in any of the hundreds of BigQuery datasets spread across several projects in your organization. New datasets are created frequently, and the team wants a centrally managed solution that automatically profiles every current and future table and publishes its findings to Security Command Center (SCC) for unified reporting. Which approach best satisfies these requirements with the least ongoing maintenance effort?

  • Enable Sensitive Data Protection discovery at the organization (or folder) level with automatic profiling and the built-in export of findings to Security Command Center.

  • Query BigQuery INFORMATION_SCHEMA metadata to locate columns with keywords such as "ssn" or "card", then forward the query results to SCC through Pub/Sub.

  • Enforce VPC Service Controls around BigQuery and export BigQuery Data Access audit logs to SCC to monitor for sensitive information.

  • Schedule a monthly SDP inspection job in each project that scans all datasets and writes results to Cloud Logging for later ingestion into SCC.

GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot