GCP Professional Data Engineer Practice Question

Your company stores PII-bearing CSV files in dozens of Cloud Storage buckets owned by different business units and streams transactional data into several BigQuery datasets located in separate projects. The CISO wants a single control plane that automatically catalogs every asset, classifies sensitive columns, and lets the security team enforce tag-based column-level access without moving or copying the underlying data. At the same time, each business unit must continue owning its own data products. Which architecture best satisfies these requirements?

  • Enable Cloud Asset Inventory feeds and trigger Cloud Functions that add IAM conditions on every bucket and dataset containing PII, letting the security team manage separate policies in each project.

  • Copy all PII files into a single Cloud Storage bucket protected by CMEK, convert them into BigQuery managed tables, apply BigQuery column-level security there, and decommission the source buckets afterward.

  • Create a Dataplex lake spanning the existing projects and onboard each bucket and BigQuery dataset with automatic metadata discovery. Grant the security team the Lake Admin role plus Data Catalog TagTemplate Admin (or Taxonomy Admin) so they can centrally create and apply policy tags to PII columns, while each business unit retains Asset Owner permissions on its buckets and datasets.

  • Expose each bucket through BigLake external tables and rely on per-project BigQuery row-level security combined with VPC Service Controls to restrict PII access.

GCP Professional Data Engineer
Storing the data
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot