GCP Professional Cloud Security Engineer Practice Question

Your security team must let an external analytics vendor query a BigQuery table to generate daily reports. The table contains several columns marked as confidential that the vendor must never see. The solution must enforce least-privilege, avoid exporting or copying data, and allow the vendor to keep using standard SQL tools through BigQuery for the next 30 days. Which approach best satisfies these requirements?

  • Create an authorized view that selects only the required fields and grant the vendor the BigQuery Data Viewer role on the view.

  • Export the required columns to Cloud Storage each night and share the objects through signed URLs that expire after 30 days.

  • Copy the table into a new dataset that omits the confidential columns and give the vendor the BigQuery Data Viewer role on that dataset.

  • Apply BigQuery column-level security tags to the confidential columns and grant the vendor BigQuery Data Viewer on the source dataset.

GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot