Cloud Digital Leader Trust and security with Google Cloud Practice Question
Which TWO features are part of Cloud Data Loss Prevention (Cloud DLP)?
⚠ Common exam trap
Google Cloud often tests the distinction between data-level security (Cloud DLP) and infrastructure-level security (vulnerability scanning, malware removal, IAM) to see if candidates confuse Cloud DLP's content inspection capabilities with broader security services.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Classification of sensitive data such as credit card numbers
Cloud DLP is Google Cloud's service for discovering, classifying, and protecting sensitive data, so option A is correct: it inspects content and metadata to detect and classify sensitive data types such as credit card numbers, using built-in infoType detectors (for example CREDIT_CARD_NUMBER). Option B is also correct because Cloud DLP provides de-identification transformations including masking, tokenization (crypto-based tokenization via CryptoKey), and encryption (format-preserving encryption, deterministic encryption, and pseudonymization) to protect detected sensitive values. Option C is not part of Cloud DLP; network vulnerability scanning is handled by Security Command Center/Web Security Scanner, not DLP. Option D is not part of Cloud DLP; malware scanning of uploaded files is performed by services such as Cloud Storage malware scanning or third-party tools, not DLP. Option E is not part of Cloud DLP; IAM policies are created and managed through IAM, not through Cloud DLP.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Classification of sensitive data such as credit card numbers
Why this is correct
Cloud DLP identifies sensitive data by applying built-in infoType detectors that match patterns like credit card numbers, which are further validated with Luhn checksum and contextual evidence. This classification step is the foundation for subsequent data protection actions, allowing organizations to discover where sensitive data resides across stored and streaming content, and even supports custom regex detectors for proprietary formats.
- ✓
De-identification of data through masking, tokenization, and encryption
Why this is correct
De-identification transforms the actual content so it can be safely used in lower-security environments. Cloud DLP provides multiple methods: masking replaces characters with symbols (e.g., XXXX), tokenization replaces a value with a randomly generated token while preserving a mapping table for reversibility, and format-preserving encryption (FPE) encrypts data so the output retains the original format. These transformations can be applied and re-identified using cryptographic keys, enabling controlled data sharing and compliance with privacy regulations.
- ✗
Network vulnerability scanning
Why it's wrong here
Network vulnerability scanning is an infrastructure security concern that involves probing services, ports, and system configurations for exploitable weaknesses. This is not a feature of Cloud DLP, which is scoped to content inspection and de-identification of data rather than network-level threat detection. On Google Cloud, such scanning is typically performed by Cloud Security Scanner for App Engine or by third-party vulnerability management tools, and DLP does not interact with network stacks.
- ✗
Removal of malware from uploaded files
Why it's wrong here
Cloud DLP does not execute files or analyze binary signatures to detect malware, as that falls into antivirus or endpoint detection and response (EDR) product categories. Its inspection engine is designed to parse text, structured data, and common file formats (like PDFs and spreadsheets) for sensitive data patterns, not malicious code. Malware removal would require a separate solution, such as VirusTotal, Chronicle, or a custom file scanning pipeline, none of which are part of Cloud DLP's core functionality.
- ✗
Creation of IAM policies
Why it's wrong here
Cloud DLP is a consumer of IAM policies but does not create them. IAM policy creation is handled by Cloud IAM, where administrators define principals, roles, and condition bindings that control access to resources like projects, buckets, and datasets. While Cloud DLP requires IAM permissions to access data and invoke services, it cannot author or modify IAM policies; its role is to inspect and protect data content, not to manage resource-level access control.
Go deeper
Related to this question
Learn chapter
Google Cloud Data Catalog
Key term
Cloud DLP
Cloud DLP (Data Loss Prevention) is a set of tools and policies that protect sensitive data stored, processed, or shared in cloud services from unauthorized access, leaks, or breaches.
Key term
Pseudonymization
Pseudonymization is a data processing technique that replaces private identifiers with artificial identifiers, or pseudonyms, to protect personal data while still allowing for analysis and processing.
About these practice questions
One of 848 original GCDL practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.