Professional Data EngineerManaging and securing dataMedium
A global logistics company uses BigQuery for analyzing shipment data. They have a dataset containing sensitive customer addresses and shipment contents. To ensure data privacy and compliance, they need to restrict access to this dataset to only authorized personnel, and all access attempts, including failed ones, must be logged for auditing purposes. Additionally, they need to track who accessed what data, when, and from where. Which combination of Google Cloud services should they use to meet these requirements?
- ACloud IAM for access control and Cloud Logging (Audit Logs) for logging
- BBigQuery Row-level Security for access control and Cloud Trace for logging
- CCloud Data Catalog for access control and Data Loss Prevention (DLP) for logging
- DBigQuery Authorized Views for access control and Stackdriver Monitoring for logging
Show answer & explanationAnswer & explanation
Correct answer: A. Cloud IAM for access control and Cloud Logging (Audit Logs) for logging
Cloud IAM is the primary service for managing access control to Google Cloud resources like BigQuery datasets. Cloud Logging, specifically Audit Logs, automatically records administrative activities and data access events, including failed attempts, providing the necessary audit trail for compliance.
Why the other options are wrong
- B. Cloud Trace is for distributed tracing, not general audit logging. BigQuery Row-level Security restricts rows, but IAM is still needed for overall dataset access.
- C. Cloud Data Catalog is for metadata management, not access control. Data Loss Prevention (DLP) is for identifying and protecting sensitive data, not general access logging.
- D. Stackdriver Monitoring focuses on metrics and uptime, not detailed audit logs for data access. BigQuery Authorized Views are for data restriction within BigQuery, not the primary access control for the dataset itself.
Cloud IAM & Cloud Audit Logs for Data Governance
Cloud IAM provides granular access control to Google Cloud resources, while Cloud Audit Logs record administrative activities and data access events, forming a crucial foundation for data governance and compliance.
- Cloud IAM defines 'who' can do 'what' on 'which' resources.
- Cloud Audit Logs capture Admin Activity, Data Access, and System Event logs.
- Data Access logs record read/write operations on user-provided data.
Memory trick: IAM grants the keys, Audit Logs record every turn, ensuring governance and trust are earned.