Professional Cloud ArchitectDesign for security and complianceMedium
A research institution is deploying a data analytics pipeline on Google Cloud that processes large volumes of anonymized patient data. While the data is anonymized, they are concerned about the potential for re-identification attacks if certain combinations of attributes are exposed. They need a service to automatically identify, classify, and, if necessary, redact or transform sensitive data within their datasets before it's used in analytics. Which Google Cloud service is designed for this purpose?
- AVPC Service Controls
- BCloud Data Loss Prevention (DLP)
- CCloud IAM
- DCloud Audit Logs
Show answer & explanationAnswer & explanation
Correct answer: B. Cloud Data Loss Prevention (DLP)
Cloud Data Loss Prevention (DLP) is purpose-built to discover, classify, and protect sensitive data. It can scan various data sources, identify specific info types (like patient IDs or quasi-identifiers), and perform de-identification techniques like redaction, tokenization, or format-preserving encryption to prevent re-identification, directly meeting the requirement.
Why the other options are wrong
- A. VPC Service Controls creates security perimeters to prevent data exfiltration, it does not scan or transform data content.
- C. Cloud IAM manages access permissions to resources, it does not scan or transform data content.
- D. Cloud Audit Logs record administrative activities and data access events, they do not scan or transform data content for sensitivity.
Cloud Data Loss Prevention (DLP)
Cloud DLP is a fully managed service that helps discover, classify, and protect sensitive data across Google Cloud and hybrid environments.
- Identifies over 150 info types (e.g., credit card numbers, PHI).
- Offers de-identification techniques (redaction, tokenization, format-preserving encryption).
- Scans structured and unstructured data.
Memory trick: DLP is your 'data detective' and 'privacy protector' for sensitive info.