PDE Storing the Data Practice Question
A company stores highly sensitive financial data in BigQuery. They need to encrypt certain columns (e.g., credit card numbers) with customer-managed encryption keys (CMEK) at the column level. Which BigQuery feature should they use?
⚠ Common exam trap
Candidates often confuse dataset-level CMEK (encrypts all data at rest in the dataset) with column-level CMEK via policy tags (encrypts specific columns with customer-managed keys), leading them to mistakenly choose dataset CMEK when the requirement is for column-level granularity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
BigQuery Data Catalog with policy tags
BigQuery supports column-level encryption with customer-managed encryption keys (CMEK) through column-level encryption using policy tags in BigQuery Data Catalog. You create a policy tag, associate a Cloud KMS key with that policy tag, and apply the policy tag to a column. BigQuery then encrypts that column with the customer-managed key. AEAD functions with Cloud KMS provide application-layer encryption of individual values, but they are not the native BigQuery CMEK feature and should not be described as CMEK.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Customer-managed encryption keys (CMEK) on the dataset
Why it's wrong here
Dataset-level CMEK encrypts all data in the dataset with one key, not selected columns such as credit card numbers. It is tempting because it is genuine CMEK, but the granularity is wrong: the stem requires column-level encryption, which dataset keys cannot provide.
- ✗
VPC Service Controls
Why it's wrong here
VPC Service Controls builds a perimeter restricting data exfiltration paths; it does not encrypt individual columns with customer-managed keys. It is tempting because it protects BigQuery data boundaries, but the stem demands column-level CMEK encryption, which perimeters cannot deliver.
- ✗
AEAD encryption functions with Cloud KMS
Why it's wrong here
AEAD functions such as AEAD.ENCRYPT accept a Cloud KMS key and encrypt individual column values, so each credit card number is protected with a customer-managed key. This satisfies the column-level CMEK requirement that dataset-level default encryption cannot meet.
- ✓
BigQuery Data Catalog with policy tags
Why this is correct
Policy tags classify columns and enforce access control through fine-grained permissions; they do not apply customer-managed encryption keys to individual columns. It is tempting because policy tags deliver column-level security, but that is access governance, not column-level CMEK encryption as the stem requires.
About these practice questions
Courseiva writes every PDE question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PDE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PDE exam.