Courseiva

Cloud Digital Leader Trust and security with Google Cloud Practice Question

Which TWO features are part of Cloud Data Loss Prevention (Cloud DLP)?

⚠ Common exam trap

Google Cloud often tests the distinction between data-level security (Cloud DLP) and infrastructure-level security (vulnerability scanning, malware removal, IAM) to see if candidates confuse Cloud DLP's content inspection capabilities with broader security services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Classification of sensitive data such as credit card numbers

Cloud DLP is Google Cloud's service for discovering, classifying, and protecting sensitive data, so option A is correct: it inspects content and metadata to detect and classify sensitive data types such as credit card numbers, using built-in infoType detectors (for example CREDIT_CARD_NUMBER). Option B is also correct because Cloud DLP provides de-identification transformations including masking, tokenization (crypto-based tokenization via CryptoKey), and encryption (format-preserving encryption, deterministic encryption, and pseudonymization) to protect detected sensitive values. Option C is not part of Cloud DLP; network vulnerability scanning is handled by Security Command Center/Web Security Scanner, not DLP. Option D is not part of Cloud DLP; malware scanning of uploaded files is performed by services such as Cloud Storage malware scanning or third-party tools, not DLP. Option E is not part of Cloud DLP; IAM policies are created and managed through IAM, not through Cloud DLP.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Classification of sensitive data such as credit card numbers

    Why this is correct

    Cloud DLP identifies sensitive data by applying built-in infoType detectors that match patterns like credit card numbers, which are further validated with Luhn checksum and contextual evidence. This classification step is the foundation for subsequent data protection actions, allowing organizations to discover where sensitive data resides across stored and streaming content, and even supports custom regex detectors for proprietary formats.

  • ✓

    De-identification of data through masking, tokenization, and encryption

    Why this is correct

    De-identification transforms the actual content so it can be safely used in lower-security environments. Cloud DLP provides multiple methods: masking replaces characters with symbols (e.g., XXXX), tokenization replaces a value with a randomly generated token while preserving a mapping table for reversibility, and format-preserving encryption (FPE) encrypts data so the output retains the original format. These transformations can be applied and re-identified using cryptographic keys, enabling controlled data sharing and compliance with privacy regulations.

  • ✗

    Network vulnerability scanning

    Why it's wrong here

    Network vulnerability scanning is an infrastructure security concern that involves probing services, ports, and system configurations for exploitable weaknesses. This is not a feature of Cloud DLP, which is scoped to content inspection and de-identification of data rather than network-level threat detection. On Google Cloud, such scanning is typically performed by Cloud Security Scanner for App Engine or by third-party vulnerability management tools, and DLP does not interact with network stacks.

  • ✗

    Removal of malware from uploaded files

    Why it's wrong here

    Cloud DLP does not execute files or analyze binary signatures to detect malware, as that falls into antivirus or endpoint detection and response (EDR) product categories. Its inspection engine is designed to parse text, structured data, and common file formats (like PDFs and spreadsheets) for sensitive data patterns, not malicious code. Malware removal would require a separate solution, such as VirusTotal, Chronicle, or a custom file scanning pipeline, none of which are part of Cloud DLP's core functionality.

  • ✗

    Creation of IAM policies

    Why it's wrong here

    Cloud DLP is a consumer of IAM policies but does not create them. IAM policy creation is handled by Cloud IAM, where administrators define principals, roles, and condition bindings that control access to resources like projects, buckets, and datasets. While Cloud DLP requires IAM permissions to access data and invoke services, it cannot author or modify IAM policies; its role is to inspect and protect data content, not to manage resource-level access control.

About these practice questions

One of 848 original GCDL practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.