PDE Storing the Data Practice Question
A company uses BigQuery for analytics and needs to ensure that certain columns containing PII are encrypted at query time so that only authorized users can decrypt. What should they use?
⚠ Common exam trap
In Google Cloud exams, a common trap is to assume that Customer-managed encryption keys (CMEK) provide column-level, application-layer encryption or query-time decryption control. CMEK only protects data at rest at the storage level, not at query time. The correct approach for column-level query-time encryption is to use BigQuery AEAD encryption functions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
BigQuery AEAD encryption functions
BigQuery AEAD encryption functions allow you to encrypt sensitive columns (e.g., PII) at query time using a user-managed key, so that only authorized users who possess the key can decrypt the data. This is the correct approach because it provides column-level, application-layer encryption that is transparent to the query engine and ensures that unauthorized users see only ciphertext.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
BigQuery AEAD encryption functions
Why this is correct
BigQuery AEAD encryption functions let you encrypt specific PII columns at query time using keys managed through Cloud KMS, so only principals holding the key can decrypt. This satisfies the requirement for column-level, query-time encryption rather than storage-level or dataset-level controls.
- ✗
VPC Service Controls
Why it's wrong here
VPC Service Controls builds a perimeter around Google Cloud services to prevent data exfiltration; it does not encrypt columns or control per-user decryption at query time. It is tempting because it restricts access to BigQuery data, but that is network perimeter control, not cryptographic column protection.
- ✗
Customer-managed encryption keys (CMEK)
Why it's wrong here
CMEK encrypts data at rest with keys you control in Cloud KMS; it does not encrypt individual columns at query time or gate decryption per user. It is tempting because it gives key control over PII, but that is storage-level encryption, not column-level query-time decryption.
- ✗
Fine-grained IAM roles
Why it's wrong here
Fine-grained IAM roles restrict which columns or rows a principal may read, but they do not encrypt PII or require decryption keys at query time. They are tempting because they limit data exposure, yet that is authorisation, not the cryptographic enforcement the scenario demands.
About these practice questions
Courseiva writes every PDE question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PDE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PDE exam.