Google PCA Design for security and compliance Practice Question
A government agency must run sensitive analytics in BigQuery while ensuring that analysts can see aggregated results but never the raw values of specific personal data columns. Analysts use SQL and must not be able to bypass the restriction by writing their own queries. The agency also needs to record who queried which columns. Which combination should the architect use?
⚠ Common exam trap
The trap here is assuming that dataset-level roles or views prevent analysts from reading sensitive columns, when only column-level policy tags enforce masking inside the query engine.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a policy tag taxonomy in Data Catalog, assign a policy tag to the sensitive columns, and grant analysts the fine-grained reader role on the tag so they see masked values, while column access is recorded in audit logs.
Column-level security in BigQuery is delivered through policy tags in Data Catalog. Assigning a policy tag to the sensitive columns and granting analysts only the fine-grained reader role on that tag causes BigQuery to return masked values for those columns while still allowing aggregation over the rest of the table. Because enforcement happens inside the query engine, analysts cannot bypass it with custom SQL, and column access is captured in data access audit logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Encrypt the sensitive columns with a customer-managed key and grant analysts the crypto key decrypter role only for aggregate queries.
Why it's wrong here
BigQuery does not apply KMS keys at the column level for query-time decryption decisions, so this does not produce the intended masking behavior. Granting a decrypter role cannot be scoped to aggregate queries, meaning an analyst with the role could decrypt the raw values. This design neither enforces the masking nor provides the column-level audit record.
- ✗
Create a view that omits the sensitive columns and grant analysts access only to the view, revoking access to the base table.
Why it's wrong here
A view can hide columns, but maintaining a separate view for every access pattern is brittle and does not record column-level reads of the base table. If analysts are ever granted base-table access for another purpose, the restriction disappears. This approach also does not produce the column-level audit trail the agency needs, and it scales poorly as the schema evolves.
- ✗
Grant analysts roles/bigquery.dataViewer on the dataset and rely on BigQuery's default access controls to prevent them from seeing sensitive columns.
Why it's wrong here
The data viewer role grants read access to the underlying tables, so analysts can query the sensitive columns directly. BigQuery's default access controls restrict dataset and table access, not individual column values, so they cannot enforce the masking requirement. This approach also provides no column-level audit trail of who read the sensitive fields, failing the logging requirement.
- ✓
Create a policy tag taxonomy in Data Catalog, assign a policy tag to the sensitive columns, and grant analysts the fine-grained reader role on the tag so they see masked values, while column access is recorded in audit logs.
Why this is correct
Policy tags in Data Catalog applied to specific columns let BigQuery return masked values to principals who hold only the fine-grained reader role on the tag, while fully privileged principals see raw data. Because the masking is enforced at the column level by BigQuery itself, analysts cannot circumvent it by rewriting SQL. Data access audit logs then record the column-level reads for the compliance requirement.
Go deeper
Related to this question
Learn chapter
Identity and Access Management (IAM)
Key term
CAN
A CAN (Controller Area Network) is a robust vehicle bus standard designed to allow microcontrollers and devices to communicate with each other without a host computer.
Key term
Table
A table is a structured collection of data organized into rows and columns, used in databases and spreadsheets to store and manage information efficiently.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.