GCP Professional Data Engineer Practice Question

Your organization is building its first Google Cloud analytics pipeline. A Dataflow job writes intermediate files to a regional Cloud Storage bucket and streams cleaned records into a BigQuery dataset. No Cloud KMS keys or additional network controls have been configured. The security lead asks whether data will still be encrypted as it moves through the pipeline and when it is stored. What must you do to guarantee encryption of the data at rest and in transit?

  • Nothing: Google Cloud automatically encrypts data in transit between services and at rest in Cloud Storage and BigQuery using Google-managed keys.

  • Configure customer-supplied encryption keys (CSEK) on the Cloud Storage bucket because Google's default encryption protects only object metadata, not object contents.

  • Enable TLS on the Dataflow job and upload custom SSL certificates so that traffic between Dataflow workers, Cloud Storage, and BigQuery is encrypted.

  • Create a Cloud KMS key and enable CMEK for both the bucket and the dataset; otherwise the data stored by Dataflow remains unencrypted at rest.

GCP Professional Data Engineer
Designing data processing systems
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot