Professional Cloud Security EngineerEnsuring data protectionMedium

A large e-commerce company uses Google Cloud BigQuery to analyze customer purchasing patterns. They need to implement fine-grained access control to ensure that only authorized analysts can view specific columns containing Personally Identifiable Information (PII), such as email addresses and phone numbers, while other analysts can still query the same tables but see masked or tokenized versions of these sensitive columns. Which BigQuery security feature should they implement?

  1. ABigQuery authorized views
  2. BBigQuery column-level security with data masking
  3. CBigQuery row-level security
  4. DBigQuery dataset access controls
Show answer & explanation

Correct answer: B. BigQuery column-level security with data masking

BigQuery column-level security with data masking allows administrators to define policies that restrict access to specific columns or apply masking functions (e.g., tokenization, hashing, nulling) to the data within those columns based on user roles or groups, providing fine-grained control over sensitive PII.

Why the other options are wrong

  • A. Authorized views can hide columns or transform data, but managing multiple views for different masking requirements can be complex and less flexible than column-level security policies.
  • C. Row-level security restricts access to entire rows based on conditions, not specific columns within a row.
  • D. Dataset access controls grant or deny access to an entire dataset, not individual columns within tables.

BigQuery Column-level Security with Data Masking

A BigQuery feature that allows you to define policies to restrict access to specific columns or apply masking transformations to sensitive data within those columns based on user roles or groups.

  • Provides fine-grained access control at the column level.
  • Supports various masking functions (e.g., hash, default, null, email).
  • Uses Policy Tags (taxonomy) to classify sensitive columns.

Memory trick: Mask columns to hide secrets, but let others see the rest.

More Ensuring data protection questions