Courseiva

Google PCA Design for security and compliance Practice Question

An organization is implementing a data loss prevention (DLP) strategy for Cloud Storage. They want to automatically scan new objects uploaded to a specific bucket and redact sensitive data. Which service and configuration should they use?

⚠ Common exam trap

Candidates often confuse Cloud DLP's batch scanning capabilities (e.g., via BigQuery or Cloud Storage inspect jobs) with the need for real-time, event-driven processing, leading them to choose Option C instead of recognizing that Cloud Functions provide the necessary automatic trigger for each new object.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Cloud Functions triggered by Cloud Storage events to call Cloud DLP API for each new object, and then store the redacted version.

It uses Cloud Functions as an event-driven compute service that triggers on Cloud Storage object finalize events. The function then calls the Cloud DLP API to inspect and redact sensitive data from the new object, and writes the redacted version back to the bucket. This provides automatic, near-real-time scanning and redaction for each uploaded object, aligning with the requirement for an automated DLP strategy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure Cloud Armor with a WAF rule to inspect and redact data as it enters the bucket.

    Why it's wrong here

    Cloud Armor filters HTTP(S) traffic at the load balancer edge; it cannot read object contents inside a bucket, so no redaction occurs. It is tempting because Cloud Armor genuinely inspects and blocks requests, which suits protecting external web applications rather than scanning stored objects.

  • ✗

    Enable Security Command Center (SCC) premium tier and configure it to scan the bucket for sensitive data.

    Why it's wrong here

    Security Command Center detects misconfigurations and threats; it does not scan object contents or redact sensitive data. It is tempting as a security scanning service, but automatic DLP inspection and redaction of new objects requires Cloud DLP with a bucket inspection job and de-identification template.

  • ✗

    Use Cloud DLP with a BigQuery external table to scan the bucket contents periodically.

    Why it's wrong here

    A BigQuery external table only exposes bucket objects as queryable rows; it cannot rewrite or redact the underlying objects, and periodic polling misses the automatic on-upload requirement. It is tempting because BigQuery can query Cloud Storage data, which suits analytics over existing files rather than DLP remediation.

  • ✓

    Use Cloud Functions triggered by Cloud Storage events to call Cloud DLP API for each new object, and then store the redacted version.

    Why this is correct

    Event-driven Cloud Functions fire on each object finalisation, invoking the Cloud DLP API to inspect and redact sensitive content before writing the sanitised object back. This satisfies automatic scanning of new uploads, which bucket-level DLP inspection alone cannot trigger per object.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.