PDE Maintaining and Automating Data Workloads Practice Question
Your company stores sensitive customer data in Cloud Storage. You need to inspect the data for personally identifiable information (PII) and de-identify it before sharing with a third party. Which Google Cloud service should you use?
⚠ Common exam trap
Candidates often confuse Cloud KMS (key management only) with Cloud DLP (inspection and de-identification), leading them to mistakenly choose Cloud KMS because they associate 'de-identify' with encryption, but Cloud KMS only manages keys, not the inspection or transformation of data content.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud Data Loss Prevention (DLP)
Cloud Data Loss Prevention (DLP) is the correct service because it is specifically designed to inspect, classify, and de-identify sensitive data such as PII in Cloud Storage. It provides built-in infoType detectors for over 150 types of PII and supports de-identification techniques like masking, tokenization, and encryption. This directly matches the requirement to inspect and de-identify data before sharing with a third party.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Security Command Center
Why it's wrong here
Security Command Center aggregates findings and posture across your organisation; it does not inspect Cloud Storage contents or de-identify records. It is tempting because it is a security service, and would be correct for detecting misconfigurations and threats across Google Cloud resources.
- ✗
Dataplex
Why it's wrong here
Dataplex is a data governance and lake management service for cataloguing, discovery and quality across distributed data; it does not scan content for PII patterns or transform records. The stem requires inspection and de-identification, which Sensitive Data Protection (DLP) performs. Dataplex would be correct for centralising metadata and enforcing governance policies across a data lake.
- ✓
Cloud Data Loss Prevention (DLP)
Why this is correct
Cloud DLP inspects data using infoType detectors to locate PII, then applies de-identification transformations such as masking, tokenisation or redaction. This satisfies both requirements: identifying sensitive customer data and removing it before sharing with the third party.
- ✗
Cloud KMS
Why it's wrong here
Cloud KMS manages encryption keys and performs cryptographic operations; it cannot scan data for PII patterns or transform it. It is tempting because KMS protects sensitive data, and would be correct for encrypting Cloud Storage objects or managing customer-managed encryption keys.
Go deeper
Related to this question
About these practice questions
This PDE question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PDE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PDE exam.