Courseiva
Storing the Data →mediumMultiple Select

PDE Storing the Data Practice Question

A data engineer needs to restrict access to BigQuery datasets such that only data from approved VPC networks can query them. They also need to audit data access. Which two security controls should they implement? (Choose two.)

⚠ Common exam trap

Google Cloud often tests the distinction between identity-based controls (IAM) and network-based controls (VPC Service Controls), leading candidates to mistakenly choose IAM roles when the requirement explicitly specifies restricting access by VPC network rather than by user identity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cloud Audit Logs

VPC Service Controls (E) is correct because it creates a service perimeter around BigQuery that restricts access to only approved VPC networks, blocking requests from outside the perimeter and mitigating data exfiltration. Cloud Audit Logs (A) is correct because it records BigQuery data access and administrative activity (Data Access audit logs must be explicitly enabled), providing the required audit trail. CMEK (B) only controls encryption key ownership, not network-based access or auditing. DLP (C) discovers and classifies sensitive data but does not restrict network access or provide access auditing. IAM roles (D) grant permissions to identities but cannot enforce VPC network origin restrictions on BigQuery.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Cloud Audit Logs

    Why this is correct

    Cloud Audit Logs record BigQuery API calls and data access events, capturing who queried which datasets and when. This satisfies the auditing half of the requirement, providing the access visibility needed alongside network-based restrictions to demonstrate compliance and investigate suspicious queries.

  • ✗

    Customer-managed encryption keys (CMEK)

    Why it's wrong here

    CMEK encrypts data at rest with keys you manage in Cloud KMS; it neither restricts queries by VPC network nor records access events. It is tempting because CMEK strengthens data-at-rest confidentiality for compliance regimes, but VPC Service Controls perimeters and Data Access audit logs are what enforce network origin and auditing here.

  • ✗

    Data Loss Prevention (DLP)

    Why it's wrong here

    Data Loss Prevention inspects and classifies sensitive data to prevent exfiltration; it neither restricts BigQuery queries by source VPC network nor records data-access audit logs. It is tempting because it is a data-security control, and would be correct when the requirement is detecting or blocking sensitive data leaving the organisation.

  • ✗

    IAM roles

    Why it's wrong here

    IAM roles grant identities permissions to BigQuery resources; they do not evaluate the querying network's origin, so they cannot enforce VPC-based restrictions. They are tempting because they are the standard BigQuery access control, and would be correct when the requirement is granting users or services appropriate dataset permissions.

  • ✓

    VPC Service Controls

    Why this is correct

    VPC Service Controls build a service perimeter around BigQuery, blocking requests that originate outside approved VPC networks regardless of IAM permissions. This satisfies the constraint that only approved networks may query the datasets, adding a network-origin boundary that IAM alone cannot enforce.

About these practice questions

Courseiva writes every PDE question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PDE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PDE exam.