Courseiva

Google PCA Design for security and compliance Practice Question

A data engineer needs to analyze data in BigQuery but must mask personally identifiable information (PII) based on user roles. Which service should they use?

⚠ Common exam trap

A common trap in Google PCA exams is confusing Cloud DLP (which is for classification and de-identification before data storage) with BigQuery column-level security (which provides runtime access control based on roles). DLP does not enforce role-based masking at query time; column-level security with policy tags does.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

BigQuery column-level security

BigQuery column-level security allows you to apply fine-grained access controls to specific columns containing PII, such as by using policy tags to restrict access based on user roles. This directly meets the requirement to mask sensitive data in BigQuery without moving or duplicating data, as it integrates with Cloud IAM to enforce role-based access at query time.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    BigQuery column-level security

    Why this is correct

    BigQuery column-level security uses policy tags in Data Catalog to restrict access to specific columns, masking or denying PII according to the user's role. This satisfies the requirement to mask personally identifiable information based on user roles without duplicating datasets.

  • ✗

    Cloud Key Management Service

    Why it's wrong here

    Cloud KMS manages encryption keys and performs cryptographic operations for data at rest or in transit; it has no mechanism to inspect query results or redact PII fields per role. BigQuery policy tags with dynamic data masking deliver the role-based masking requirement.

  • ✗

    Cloud Data Catalog

    Why it's wrong here

    Cloud Data Catalog is a metadata inventory for discovery, tagging and governance; it stores and surfaces policy tags but does not itself rewrite or mask query results. BigQuery column-level security with policy tags and dynamic data masking enforces role-based PII masking at query time.

  • ✗

    Cloud Data Loss Prevention (DLP)

    Why it's wrong here

    Cloud DLP discovers, classifies and de-identifies sensitive data in stored datasets or streams, but it does not enforce role-based masking inside BigQuery query results. BigQuery policy tags with dynamic data masking apply per-role redaction at query time, which is the stated requirement.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.