Courseiva

PDE Preparing and Using Data for Analysis Practice Question

You are using Looker to model data from BigQuery. You have a dimension that should be filtered by a user attribute (e.g., user's region). Which LookML concept allows you to apply dynamic row-level security based on user attributes?

⚠ Common exam trap

PDE often tests the distinction between modeling constructs (derived tables, custom fields) and security constructs (access filters) — candidates pick derived tables thinking they can embed security logic, but derived tables are for data transformation, not dynamic user-based filtering.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Access filter

Access filters in LookML allow you to apply row-level security by referencing user attributes, which are values passed from the Looker user's account or via SSO. By using an access filter on a dimension, you can dynamically restrict the data a user sees based on their attribute (e.g., region), ensuring they only view rows matching their assigned region. This is the standard LookML mechanism for dynamic row-level security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Custom field

    Why it's wrong here

    A custom field is a user-defined calculation or filter created in the Explore UI; it cannot enforce row-level security because users can alter or remove it. It tempts as a quick per-user filter, and would be correct for ad-hoc analysis, not governed access control.

  • ✗

    Derived table

    Why it's wrong here

    Derived tables are LookML queries that create new virtual tables from SQL, used for transforming or joining data before modelling. They cannot read user attributes at query time, so they cannot enforce row-level security. Access filters, applied via sql_always_where with user attributes, are the mechanism for dynamic row-level filtering.

  • ✓

    Access filter

    Why this is correct

    An access filter applies a user attribute to a dimension or field, restricting each user's query results to rows matching their attribute value. This delivers dynamic row-level security in Looker without duplicating models per region.

  • ✗

    Required access grant

    Why it's wrong here

    Required access grants gate access to Explores and models, not rows within a query, so they cannot filter a dimension by user attribute. They tempt because they also use user attributes, and would be correct for restricting which users may run a given Explore.

About these practice questions

Courseiva writes every PDE question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PDE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PDE exam.