Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 298 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 298

Select 3Google Cloud Platform

Your organization stores customer data in Google Cloud Storage buckets. To meet compliance requirements, you need to ensure that any Personally Identifiable Information (PII) such as Social Security Numbers (SSNs) is discovered and either redacted or pseudonymized before data is accessed by downstream systems. Which of the following steps should you take to achieve this?

  1. A

    Use Cloud Data Loss Prevention (DLP) to scan the data for PII in the Cloud Storage buckets.

  2. B

    Configure Cloud DLP to apply a transformation such as 'Redact with InfoType' or 'Replace with FPE' for detected PII.

  3. C

    Grant all users the Owner role on the Cloud Storage bucket to ensure access for reviewing sensitive data.

  4. D

    Use Pub/Sub to send the scanned data to an external system for further manual review before redaction.

  5. E

    Set up a Cloud Function to trigger Cloud DLP scans automatically whenever new files are uploaded to the Cloud Storage bucket.

Show answer and explanation

Correct answers: A, B, E

Explanation

To protect sensitive data, Cloud DLP should be used to discover and transform PII in Cloud Storage buckets. Configuring automated workflows using tools like Cloud Functions ensures that sensitive data protection is applied consistently and in real-time. Granting excessive permissions or relying on manual processes introduces security and operational risks that should be avoided.

  • A. Correct.

    Correct: Cloud Data Loss Prevention (DLP) is the recommended tool in Google Cloud for scanning and discovering sensitive data such as PII within Cloud Storage buckets.

  • B. Correct.

    Correct: Cloud DLP can apply transformations like redaction or pseudonymization (e.g., format-preserving encryption) to detected PII, which satisfies compliance requirements.

  • C. Incorrect.

    Incorrect: Granting all users the Owner role violates the principle of least privilege and exposes sensitive data to unnecessary risk.

  • D. Incorrect.

    Incorrect: While Pub/Sub can be used in workflows, relying on manual review for redaction is inefficient and not scalable for automated sensitive data protection.

  • E. Correct.

    Correct: Setting up a Cloud Function to trigger DLP scans automatically ensures that all new data in the bucket is processed in real-time for sensitive data protection.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam