Courseiva

Google PCA Design and plan a cloud solution architecture Practice Question

A healthcare analytics company must build a data platform on Google Cloud that stores patient records subject to strict privacy rules. The design must ensure that analysts can query aggregated data without being able to read individual patient identifiers, and that all access to the raw records is logged for audit. Which two design choices should the architect include? (Choose two.)

⚠ Common exam trap

The trap here is believing encryption at rest hides data from authorized users, when keys and IAM still allow plaintext reads.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Sensitive Data Protection (Cloud DLP) to de-identify or tokenize patient identifiers before loading records into the analytics dataset.

The two goals are preventing analysts from reading identifiers and logging all access to raw records. De-identifying or tokenizing identifiers before the analytics layer sees them meets the first goal, and enabling Data Access audit logs on the services holding raw records meets the second. Broad viewer grants, generic storage protections, and encryption alone do not de-identify data or provide the necessary read-level audit trail.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use Sensitive Data Protection (Cloud DLP) to de-identify or tokenize patient identifiers before loading records into the analytics dataset.

    Why this is correct

    Sensitive Data Protection can detect and transform identifiable fields such as names and medical record numbers, producing de-identified or tokenized output that analysts can query without seeing raw identifiers. This directly satisfies the requirement that aggregated analysis be possible while individual identifiers remain unreadable, and it can be applied during ingestion so the analytics layer never holds the original values.

  • ✗

    Store raw records in a Cloud Storage bucket with uniform bucket-level access and rely on object versioning for protection.

    Why it's wrong here

    Uniform bucket-level access and object versioning improve access control consistency and protect against accidental overwrites, but they do not de-identify data or produce audit records of who read it. Neither feature addresses the core privacy goal of preventing analysts from seeing individual identifiers, and versioning is a durability control rather than a privacy or audit control.

  • ✗

    Encrypt the raw records with customer-managed encryption keys in Cloud KMS and rotate the keys every 90 days.

    Why it's wrong here

    CMEK and key rotation strengthen cryptographic control, but anyone with authorized access and the decryption path can still read the plaintext identifiers, so this does not prevent analysts from seeing individual records. Encryption at rest is a baseline control, not a de-identification technique, and it does not generate the access audit trail the scenario requires.

  • ✓

    Enable Cloud Audit Logs Data Access logging on the services that store or serve the raw patient records.

    Why this is correct

    Data Access audit logs record reads and writes against services such as Cloud Storage and BigQuery, capturing who accessed raw records and when. Enabling these logs is what makes the audit requirement achievable, because Admin Activity logs alone do not capture data reads. This choice complements de-identification by covering the paths where raw data still exists.

  • ✗

    Grant all analysts the BigQuery Data Viewer role at the project level so they can explore datasets efficiently.

    Why it's wrong here

    Project-level Data Viewer would let analysts read every dataset in the project, including any raw tables, defeating the goal of preventing access to individual identifiers. Even with de-identified data present, broad grants violate least privilege and undermine the privacy design. Access should instead be scoped to the de-identified dataset, and raw data access restricted to a small group.

About these practice questions

Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.