Google Professional Data Engineer exam dumps

Google Professional Data Engineer practice question 5 of 279

Professional Data Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Data Engineer Question 5

Select 2Google Cloud Platform

Your organization has a Google Cloud project where sensitive financial data is processed. You need to ensure that only a specific group of users can access this data and that any access attempt is logged for auditing purposes. Which combination of actions should you take to meet these requirements?

  1. A

    Assign the 'Owner' role to the specific group of users at the project level.

  2. B

    Use Cloud IAM to grant the 'Viewer' role to the specific group of users on the sensitive data resources.

  3. C

    Create a custom IAM role with the necessary permissions and assign it to the specific group of users.

  4. D

    Enable Audit Logs for the project and ensure 'Data Access' logs are included.

  5. E

    Apply an organization policy to restrict access to sensitive data resources to only the specific group of users.

Show answer and explanation

Correct answers: C, D

Explanation

To meet the requirements, you need to ensure the group has access only to sensitive financial data and that access attempts are logged. A custom IAM role provides the exact permissions required, adhering to the principle of least privilege. Enabling 'Data Access' logs ensures all access attempts are tracked for auditing. Other options either violate security best practices or do not fulfill the scenario requirements.

  • A. Incorrect.

    Assigning the 'Owner' role at the project level gives users full administrative control over the project, including permissions they don't need for accessing sensitive financial data. This violates the principle of least privilege.

  • B. Incorrect.

    The 'Viewer' role grants read-only access to resources, but it may also allow access to non-sensitive resources unintentionally. It is not fine-grained enough for sensitive data.

  • C. Correct.

    Creating a custom IAM role with only the necessary permissions ensures that the specific group of users has the exact level of access required for sensitive data, following the principle of least privilege.

  • D. Correct.

    Enabling Audit Logs and ensuring 'Data Access' logs are included allows you to track all access attempts to the sensitive data, which is essential for compliance and auditing purposes.

  • E. Incorrect.

    Applying an organization policy can restrict access at a higher level, but this does not inherently grant permissions to the specific group. Instead, it enforces restrictions, which is not the requirement in this scenario.

Timed practice exam

Take a Google Professional Data Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam