Professional Cloud Security EngineerEnsuring data protectionMedium

A healthcare organization stores patient records in BigQuery. Due to strict compliance requirements, they must ensure that personally identifiable information (PII) within specific columns is automatically identified and masked when queried by non-authorized personnel. Which Google Cloud service should they implement to achieve this?

  1. ACloud SQL Data Masking
  2. BCloud Identity-Aware Proxy (IAP)
  3. CData Loss Prevention (DLP) with BigQuery data profiles
  4. DBigQuery Column-level Security with Data Masking
Show answer & explanation

Correct answer: D. BigQuery Column-level Security with Data Masking

BigQuery Column-level Security, combined with Data Masking, allows organizations to define policies that automatically mask sensitive data in specific columns based on the user's permissions, ensuring PII is protected during queries. DLP can identify PII but doesn't natively mask it during BigQuery query time for authorized users.

Why the other options are wrong

  • A. Cloud SQL Data Masking is for Cloud SQL, not BigQuery.
  • B. IAP controls access to applications, not column-level data masking within BigQuery.
  • C. DLP can discover and classify sensitive data, but BigQuery's native column-level security and data masking features are used to apply masking during queries.

BigQuery Column-level Security with Data Masking

BigQuery feature that allows granular access control and dynamic data masking on individual columns within tables.

  • Protects sensitive data from unauthorized views.
  • Applies masking policies based on user permissions.
  • Ensures compliance with data privacy regulations.

Memory trick: BigQuery masks PII, keeping patient data safe and unseen.

More Ensuring data protection questions