Professional Cloud ArchitectDesign for security and complianceMedium

A research institution is deploying a data analytics pipeline on Google Cloud that processes large volumes of anonymized patient data. While the data is anonymized, they are concerned about the potential for re-identification attacks if certain combinations of attributes are exposed. They need a service to automatically identify, classify, and, if necessary, redact or transform sensitive data within their datasets before it's used in analytics. Which Google Cloud service is designed for this purpose?

  1. AVPC Service Controls
  2. BCloud Data Loss Prevention (DLP)
  3. CCloud IAM
  4. DCloud Audit Logs
Show answer & explanation

Correct answer: B. Cloud Data Loss Prevention (DLP)

Cloud Data Loss Prevention (DLP) is purpose-built to discover, classify, and protect sensitive data. It can scan various data sources, identify specific info types (like patient IDs or quasi-identifiers), and perform de-identification techniques like redaction, tokenization, or format-preserving encryption to prevent re-identification, directly meeting the requirement.

Why the other options are wrong

  • A. VPC Service Controls creates security perimeters to prevent data exfiltration, it does not scan or transform data content.
  • C. Cloud IAM manages access permissions to resources, it does not scan or transform data content.
  • D. Cloud Audit Logs record administrative activities and data access events, they do not scan or transform data content for sensitivity.

Cloud Data Loss Prevention (DLP)

Cloud DLP is a fully managed service that helps discover, classify, and protect sensitive data across Google Cloud and hybrid environments.

  • Identifies over 150 info types (e.g., credit card numbers, PHI).
  • Offers de-identification techniques (redaction, tokenization, format-preserving encryption).
  • Scans structured and unstructured data.

Memory trick: DLP is your 'data detective' and 'privacy protector' for sensitive info.

More Design for security and compliance questions