You protected sensitive columns with policy tags and used an authorized dataset, but the analytics team still sees restricted columns. What should you do? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Enforce access controls on the policy tag taxonomy to restrict column access..
Why this is the answer
The analytics team can still see restricted columns because policy tags, while applied, require explicit access control enforcement on the taxonomy itself. By enforcing access controls on the policy tag taxonomy, you directly control who can view data associated with those tags, ensuring the analytics team loses access to the sensitive columns. Removing Data Catalog fine-grained reader roles for sensitive policy tags from analytics team members is also necessary. This directly revokes their permission to view data classified under those specific policy tags, addressing the problem of them seeing restricted columns. Creating separate authorized datasets or replacing with an authorized view with row-level security are workarounds that don't directly address the misconfiguration of policy tag access. Removing the bigquery.dataViewer role is too broad and would prevent them from seeing any data in the dataset, not just the restricted columns.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed