Courseiva
Storing the Data →hardMultiple Choice

PDE Storing the Data Practice Question

A company stores highly sensitive financial data in BigQuery. They need to encrypt certain columns (e.g., credit card numbers) with customer-managed encryption keys (CMEK) at the column level. Which BigQuery feature should they use?

⚠ Common exam trap

Candidates often confuse dataset-level CMEK (encrypts all data at rest in the dataset) with column-level CMEK via policy tags (encrypts specific columns with customer-managed keys), leading them to mistakenly choose dataset CMEK when the requirement is for column-level granularity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

BigQuery Data Catalog with policy tags

BigQuery supports column-level encryption with customer-managed encryption keys (CMEK) through column-level encryption using policy tags in BigQuery Data Catalog. You create a policy tag, associate a Cloud KMS key with that policy tag, and apply the policy tag to a column. BigQuery then encrypts that column with the customer-managed key. AEAD functions with Cloud KMS provide application-layer encryption of individual values, but they are not the native BigQuery CMEK feature and should not be described as CMEK.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Customer-managed encryption keys (CMEK) on the dataset

    Why it's wrong here

    Dataset-level CMEK encrypts all data in the dataset with one key, not selected columns such as credit card numbers. It is tempting because it is genuine CMEK, but the granularity is wrong: the stem requires column-level encryption, which dataset keys cannot provide.

  • ✗

    VPC Service Controls

    Why it's wrong here

    VPC Service Controls builds a perimeter restricting data exfiltration paths; it does not encrypt individual columns with customer-managed keys. It is tempting because it protects BigQuery data boundaries, but the stem demands column-level CMEK encryption, which perimeters cannot deliver.

  • ✗

    AEAD encryption functions with Cloud KMS

    Why it's wrong here

    AEAD functions such as AEAD.ENCRYPT accept a Cloud KMS key and encrypt individual column values, so each credit card number is protected with a customer-managed key. This satisfies the column-level CMEK requirement that dataset-level default encryption cannot meet.

  • ✓

    BigQuery Data Catalog with policy tags

    Why this is correct

    Policy tags classify columns and enforce access control through fine-grained permissions; they do not apply customer-managed encryption keys to individual columns. It is tempting because policy tags deliver column-level security, but that is access governance, not column-level CMEK encryption as the stem requires.

About these practice questions

Courseiva writes every PDE question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PDE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PDE exam.