PDE Preparing and Using Data for Analysis Practice Question
You are using Looker to model data from BigQuery. You have a dimension that should be filtered by a user attribute (e.g., user's region). Which LookML concept allows you to apply dynamic row-level security based on user attributes?
⚠ Common exam trap
PDE often tests the distinction between modeling constructs (derived tables, custom fields) and security constructs (access filters) — candidates pick derived tables thinking they can embed security logic, but derived tables are for data transformation, not dynamic user-based filtering.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Access filter
Access filters in LookML allow you to apply row-level security by referencing user attributes, which are values passed from the Looker user's account or via SSO. By using an access filter on a dimension, you can dynamically restrict the data a user sees based on their attribute (e.g., region), ensuring they only view rows matching their assigned region. This is the standard LookML mechanism for dynamic row-level security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Custom field
Why it's wrong here
A custom field is a user-defined calculation or filter created in the Explore UI; it cannot enforce row-level security because users can alter or remove it. It tempts as a quick per-user filter, and would be correct for ad-hoc analysis, not governed access control.
- ✗
Derived table
Why it's wrong here
Derived tables are LookML queries that create new virtual tables from SQL, used for transforming or joining data before modelling. They cannot read user attributes at query time, so they cannot enforce row-level security. Access filters, applied via sql_always_where with user attributes, are the mechanism for dynamic row-level filtering.
- ✓
Access filter
Why this is correct
An access filter applies a user attribute to a dimension or field, restricting each user's query results to rows matching their attribute value. This delivers dynamic row-level security in Looker without duplicating models per region.
- ✗
Required access grant
Why it's wrong here
Required access grants gate access to Explores and models, not rows within a query, so they cannot filter a dimension by user attribute. They tempt because they also use user attributes, and would be correct for restricting which users may run a given Explore.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PDE question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PDE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PDE exam.