A data analytics team is building a solution to process customer data for personalized marketing campaigns. The data pipeline involves extracting data from various sources, transforming it, and loading it into a data warehouse. Due to the sensitive nature of customer data, the solution must ensure that all data in transit between services is encrypted, and any personally identifiable information (PII) is automatically de-identified before being stored in the data warehouse. Which Google Cloud services should you recommend to meet these security requirements?
- ACloud VPN for secure network connections and Cloud KMS for encryption keys.
- BData Loss Prevention (DLP) for PII de-identification and Google-managed encryption in transit by default.
- CVPC Service Controls for data perimeter and Cloud Audit Logs for access monitoring.
- DCloud Interconnect for private network connectivity and Customer-Managed Encryption Keys (CMEK) for data at rest.
Show answer & explanationAnswer & explanation
Correct answer: B. Data Loss Prevention (DLP) for PII de-identification and Google-managed encryption in transit by default.
Google Cloud services encrypt data in transit by default, addressing the 'encryption in transit' requirement without explicit setup. The Data Loss Prevention (DLP) API is specifically designed to scan, classify, and de-identify sensitive data like PII before storage, directly meeting the de-identification requirement.
Why the other options are wrong
- A. Cloud VPN provides secure network but doesn't handle PII de-identification. Cloud KMS manages keys, not encryption in transit itself, which is typically handled by default for GCP services.
- C. VPC Service Controls prevent data exfiltration, and Cloud Audit Logs monitor access, but neither performs PII de-identification or guarantees encryption in transit (which is a default behavior rather than a service you 'implement').
- D. Cloud Interconnect provides private network connectivity, and CMEK is for encryption at rest. Neither directly addresses PII de-identification or the default encryption in transit for internal GCP services.
DLP & Default Encryption in Transit
Google Cloud's Data Loss Prevention (DLP) API identifies and de-identifies sensitive data (like PII). Google Cloud services encrypt data in transit by default using TLS/HTTPS for communication between services.
- DLP offers various de-identification techniques (redaction, tokenization, masking).
- All data moving between Google Cloud services is encrypted by default.
- External traffic to GCP services typically uses HTTPS/TLS for secure transit.
Memory trick: Data on its journey must always be locked (encrypted) and then wear a disguise (de-identified) before resting.