Courseiva

PDE Maintaining and Automating Data Workloads Practice Question

Your company stores sensitive customer data in Cloud Storage. You need to inspect the data for personally identifiable information (PII) and de-identify it before sharing with a third party. Which Google Cloud service should you use?

⚠ Common exam trap

Candidates often confuse Cloud KMS (key management only) with Cloud DLP (inspection and de-identification), leading them to mistakenly choose Cloud KMS because they associate 'de-identify' with encryption, but Cloud KMS only manages keys, not the inspection or transformation of data content.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cloud Data Loss Prevention (DLP)

Cloud Data Loss Prevention (DLP) is the correct service because it is specifically designed to inspect, classify, and de-identify sensitive data such as PII in Cloud Storage. It provides built-in infoType detectors for over 150 types of PII and supports de-identification techniques like masking, tokenization, and encryption. This directly matches the requirement to inspect and de-identify data before sharing with a third party.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Security Command Center

    Why it's wrong here

    Security Command Center aggregates findings and posture across your organisation; it does not inspect Cloud Storage contents or de-identify records. It is tempting because it is a security service, and would be correct for detecting misconfigurations and threats across Google Cloud resources.

  • ✗

    Dataplex

    Why it's wrong here

    Dataplex is a data governance and lake management service for cataloguing, discovery and quality across distributed data; it does not scan content for PII patterns or transform records. The stem requires inspection and de-identification, which Sensitive Data Protection (DLP) performs. Dataplex would be correct for centralising metadata and enforcing governance policies across a data lake.

  • ✓

    Cloud Data Loss Prevention (DLP)

    Why this is correct

    Cloud DLP inspects data using infoType detectors to locate PII, then applies de-identification transformations such as masking, tokenisation or redaction. This satisfies both requirements: identifying sensitive customer data and removing it before sharing with the third party.

  • ✗

    Cloud KMS

    Why it's wrong here

    Cloud KMS manages encryption keys and performs cryptographic operations; it cannot scan data for PII patterns or transform it. It is tempting because KMS protects sensitive data, and would be correct for encrypting Cloud Storage objects or managing customer-managed encryption keys.

About these practice questions

This PDE question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PDE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PDE exam.