Google PCA Design for security and compliance Practice Question
A data engineer needs to analyze data in BigQuery but must mask personally identifiable information (PII) based on user roles. Which service should they use?
⚠ Common exam trap
A common trap in Google PCA exams is confusing Cloud DLP (which is for classification and de-identification before data storage) with BigQuery column-level security (which provides runtime access control based on roles). DLP does not enforce role-based masking at query time; column-level security with policy tags does.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
BigQuery column-level security
BigQuery column-level security allows you to apply fine-grained access controls to specific columns containing PII, such as by using policy tags to restrict access based on user roles. This directly meets the requirement to mask sensitive data in BigQuery without moving or duplicating data, as it integrates with Cloud IAM to enforce role-based access at query time.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
BigQuery column-level security
Why this is correct
BigQuery column-level security uses policy tags in Data Catalog to restrict access to specific columns, masking or denying PII according to the user's role. This satisfies the requirement to mask personally identifiable information based on user roles without duplicating datasets.
- ✗
Cloud Key Management Service
Why it's wrong here
Cloud KMS manages encryption keys and performs cryptographic operations for data at rest or in transit; it has no mechanism to inspect query results or redact PII fields per role. BigQuery policy tags with dynamic data masking deliver the role-based masking requirement.
- ✗
Cloud Data Catalog
Why it's wrong here
Cloud Data Catalog is a metadata inventory for discovery, tagging and governance; it stores and surfaces policy tags but does not itself rewrite or mask query results. BigQuery column-level security with policy tags and dynamic data masking enforces role-based PII masking at query time.
- ✗
Cloud Data Loss Prevention (DLP)
Why it's wrong here
Cloud DLP discovers, classifies and de-identifies sensitive data in stored datasets or streams, but it does not enforce role-based masking inside BigQuery query results. BigQuery policy tags with dynamic data masking apply per-role redaction at query time, which is the stated requirement.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
IAM Policies, Service Accounts, and Auditing
Key term
Cloud IAM
Cloud IAM (Identity and Access Management) is a framework of policies and technologies that ensures the right individuals have appropriate access to cloud resources at the right time and for the right reasons.
Key term
Service
A service is a software component or system that performs a specific function and is available to be used by other programs or users over a network.
About these practice questions
This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.