PCSE Ensuring Data Protection Practice Question
A company needs to detect and redact sensitive data such as email addresses and phone numbers from documents stored in Cloud Storage. They plan to use Cloud DLP. Which two resources must they create first? (Choose TWO).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A de-identification template with a redaction transform (e.g., MaskingConfig)
To use Cloud DLP for scanning and redacting, you need two templates: an inspection template that defines what to look for (infoTypes like EMAIL_ADDRESS, PHONE_NUMBER) and a de-identification template that defines how to redact the sensitive data (e.g., using MaskingConfig). Option C is the inspection template, and option B is the de-identification template. You can then create a DLP job that references both templates and targets the Cloud Storage bucket. A job trigger is for scheduled scans, not mandatory for a one-time job. A key ring is not directly needed for DLP.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A DLP job trigger
Why it's wrong here
A job trigger is for recurring scans, but a one-time job can be created directly.
- ✓
A de-identification template with a redaction transform (e.g., MaskingConfig)
Why this is correct
The de-identification template specifies how to redact the detected data.
- ✓
An inspection template with infoTypes EMAIL_ADDRESS and PHONE_NUMBER
Why this is correct
The inspection template defines the sensitive data types to detect.
- ✗
A Cloud KMS key ring
Why it's wrong here
Cloud KMS is not required for basic DLP inspection and redaction.
- ✗
A BigQuery dataset
Why it's wrong here
BigQuery is not needed; the source is Cloud Storage.
Go deeper
Related to this question
About these practice questions
This PCSE question is part of Courseiva's 960-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCSE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCSE exam.