A security team needs to detect and redact personally identifiable information (PII) in documents stored in Cloud Storage before sharing them with external partners. Which two Google Cloud services should they use together? (Choose two.)
The Cloud DLP API inspects content, identifies PII using infoType detectors, and performs de-identification such as redaction or masking. It satisfies the detection and redaction requirement directly, providing the inspection engine that processes documents before external sharing.
Why this answer
The Cloud Data Loss Prevention (DLP) API (A) is the correct service for detecting and redacting personally identifiable information, since it provides infoType detectors and de-identification transforms such as redaction, masking, and tokenization that can scan and sanitize sensitive data. Cloud Storage (B) is also correct because the documents being scanned and shared reside in Cloud Storage buckets, and DLP integrates directly with Cloud Storage to inspect and de-identify objects in place or on export. Together, DLP performs the PII detection and redaction while Cloud Storage holds the source and destination documents, matching the scenario's requirement to sanitize files before external sharing.
Cloud KMS (C) only manages encryption keys and cannot detect or redact PII content. Cloud Dataflow (D) is a data processing pipeline service that could orchestrate jobs but does not itself provide PII detection or redaction logic. Cloud NAT (E) is a networking service for outbound internet access and is unrelated to data inspection or redaction.
Exam trap
PCA often tests whether candidates confuse the service that detects/redacts sensitive data (DLP) with services that merely move, encrypt, or process it (Dataflow, KMS, Storage).