GCP Professional Cloud Security Engineer Practice Question

Your security team must automatically locate Social Security numbers and other personally identifiable information that may be stored in both BigQuery tables and Cloud Storage buckets scattered across multiple projects. They also need the option to create an anonymized copy of any table or file that contains matches so analysts can query the data without viewing raw identifiers. The solution should run on a continuous schedule and surface classification results to Google Cloud's metadata catalog with minimal ongoing maintenance. Which design best satisfies these requirements?

  • Export inventories from each project to Cloud Asset Inventory, then trigger a Cloud Data Fusion pipeline with regex detectors to flag PII and write tags back to Data Catalog.

  • Enable organization-level discovery in Sensitive Data Protection, select BigQuery and Cloud Storage as scan targets, and create a de-identification template that a recurring transformation job uses to write sanitized copies to a dedicated analytics dataset or bucket.

  • Configure Object Lifecycle Management to move objects older than 30 days to Nearline storage and apply BigQuery column-level policy tags to sensitive columns in the data warehouse.

  • Place all projects behind a VPC Service Controls perimeter, enable CMEK on BigQuery and Cloud Storage, and use Cloud Scheduler to launch a nightly gsutil and bq command script that searches for sensitive strings.

GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot