Professional Data EngineerEnsuring solution qualityEasy

A global e-commerce company is building a new data platform on Google Cloud. They need to ensure that customer data, including personally identifiable information (PII), is stored securely and processed in compliance with various regional data residency regulations. The data processing pipelines involve Dataflow jobs that transform and load data into BigQuery. Which Google Cloud service should be primarily leveraged to automatically identify and categorize sensitive data across these services?

  1. ACloud KMS
  2. BCloud DLP
  3. CSecurity Command Center
  4. DCloud Audit Logs
Show answer & explanation

Correct answer: B. Cloud DLP

Cloud DLP is specifically designed for discovering, classifying, and protecting sensitive data across Google Cloud services and on-premises, making it ideal for identifying PII to ensure compliance.

Why the other options are wrong

  • A. Cloud KMS is used for managing encryption keys, not for data identification and classification.
  • C. Security Command Center provides a centralized security management and risk platform, but it relies on other services like DLP for sensitive data discovery.
  • D. Cloud Audit Logs record administrative activities and data access events but do not automatically identify or categorize sensitive data content.

Cloud DLP for Sensitive Data Discovery

Cloud Data Loss Prevention (DLP) is a fully managed service designed to discover, classify, and protect sensitive data at scale.

  • Identifies over 150 types of sensitive data (e.g., PII, financial, credentials).
  • Works across various data sources (Cloud Storage, BigQuery, Datastores, images, text).
  • Offers de-identification techniques like tokenization, masking, and redaction.

Memory trick: Discover, Classify, Protect: DLP is the data's best detective.

More Ensuring solution quality questions