Google Professional Data Engineer exam dumps

Google Professional Data Engineer practice question 2 of 279

Professional Data Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Data Engineer Question 2

Select 3Google Cloud Platform

You are designing a data pipeline that processes sensitive customer data for a financial institution using Google Cloud. To meet security and compliance requirements, you need to ensure data is encrypted both in transit and at rest, restrict access based on roles, and maintain an audit log of all access to the data. Which of the following approaches would best meet these requirements?

  1. A

    Use Cloud Storage with Customer-Managed Encryption Keys (CMEK) for storing data and enable audit logging.

  2. B

    Configure VPC Service Controls to restrict data movement across networks and secure sensitive resources.

  3. C

    Encrypt data only when it is at rest, as encryption in transit is handled automatically by Google Cloud services.

  4. D

    Use Identity and Access Management (IAM) to assign roles and permissions to users and services accessing the data.

  5. E

    Disable audit logging to improve the performance of the pipeline.

Show answer and explanation

Correct answers: A, B, D

Explanation

To design for security and compliance in this scenario, you must encrypt data both in transit and at rest, restrict access using IAM roles, and enable audit logging to track access. Additionally, VPC Service Controls provide an extra layer of security by restricting data movement across networks. Disabling audit logging or relying solely on encryption at rest does not meet compliance and security requirements.

  • A. Correct.

    Using Cloud Storage with Customer-Managed Encryption Keys (CMEK) ensures that sensitive data is encrypted at rest, and enabling audit logging helps maintain a record of access for compliance purposes.

  • B. Correct.

    Configuring VPC Service Controls helps prevent unauthorized data movement and enhances security by securing sensitive resources within a defined perimeter.

  • C. Incorrect.

    Encrypting data only when at rest is insufficient because compliance often requires encryption both in transit and at rest. Google Cloud does handle encryption in transit, but this should not be ignored as part of the design.

  • D. Correct.

    Using IAM to assign roles and permissions ensures that access to sensitive data is restricted based on the principle of least privilege, which is a critical security best practice.

  • E. Incorrect.

    Disabling audit logging compromises compliance and security since you lose visibility into who accessed the data and when, which is essential for meeting regulatory requirements.

Timed practice exam

Take a Google Professional Data Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam