Google PCA Design for security and compliance Practice Question
An organization is implementing a data loss prevention (DLP) strategy for Cloud Storage. They want to automatically scan new objects uploaded to a specific bucket and redact sensitive data. Which service and configuration should they use?
⚠ Common exam trap
Candidates often confuse Cloud DLP's batch scanning capabilities (e.g., via BigQuery or Cloud Storage inspect jobs) with the need for real-time, event-driven processing, leading them to choose Option C instead of recognizing that Cloud Functions provide the necessary automatic trigger for each new object.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Cloud Functions triggered by Cloud Storage events to call Cloud DLP API for each new object, and then store the redacted version.
It uses Cloud Functions as an event-driven compute service that triggers on Cloud Storage object finalize events. The function then calls the Cloud DLP API to inspect and redact sensitive data from the new object, and writes the redacted version back to the bucket. This provides automatic, near-real-time scanning and redaction for each uploaded object, aligning with the requirement for an automated DLP strategy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure Cloud Armor with a WAF rule to inspect and redact data as it enters the bucket.
Why it's wrong here
Cloud Armor filters HTTP(S) traffic at the load balancer edge; it cannot read object contents inside a bucket, so no redaction occurs. It is tempting because Cloud Armor genuinely inspects and blocks requests, which suits protecting external web applications rather than scanning stored objects.
- ✗
Enable Security Command Center (SCC) premium tier and configure it to scan the bucket for sensitive data.
Why it's wrong here
Security Command Center detects misconfigurations and threats; it does not scan object contents or redact sensitive data. It is tempting as a security scanning service, but automatic DLP inspection and redaction of new objects requires Cloud DLP with a bucket inspection job and de-identification template.
- ✗
Use Cloud DLP with a BigQuery external table to scan the bucket contents periodically.
Why it's wrong here
A BigQuery external table only exposes bucket objects as queryable rows; it cannot rewrite or redact the underlying objects, and periodic polling misses the automatic on-upload requirement. It is tempting because BigQuery can query Cloud Storage data, which suits analytics over existing files rather than DLP remediation.
- ✓
Use Cloud Functions triggered by Cloud Storage events to call Cloud DLP API for each new object, and then store the redacted version.
Why this is correct
Event-driven Cloud Functions fire on each object finalisation, invoking the Cloud DLP API to inspect and redact sensitive content before writing the sanitised object back. This satisfies automatic scanning of new uploads, which bucket-level DLP inspection alone cannot trigger per object.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
Learn chapter
Google Cloud Compute Options Overview
Key term
Cloud Functions
Cloud Functions are serverless compute services that let you run single-purpose code in response to events without managing servers.
Key term
Data
Data is raw, unprocessed information, like numbers, words, or measurements, that can be stored, processed, and analyzed by computers.
About these practice questions
This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.