nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #67

When working with agents in a support center via online chat, an organization's customers often share pictures of their documents with personally identifiable information (PII). The organization…

The correct answer is C. Use the image inspection and redaction actions of the DLP API to redact PII from the images. The concern is PII appearing in images (pictures of documents) shared by customers. Cloud DLP's image inspection and redaction features can detect PII within images and redact (blur or mask) those regions before the image is stored, preserving the non-PII portions of the chat…

Submitted by brentm· Apr 18, 2026Ensuring data protection

Question

When working with agents in a support center via online chat, an organization's customers often share pictures of their documents with personally identifiable information (PII). The organization that owns the support center is concerned that the PII is being stored in their databases as part of the regular chat logs they retain for review by internal or external analysts for customer service trend analysis. Which Google Cloud solution should the organization use to help resolve this concern for the customer while still maintaining data utility?

Options

  • AUse Cloud Key Management Service (KMS) to encrypt the PII data shared by customers before
  • BUse Object Lifecycle Management to make sure that all chat records with PII in them are
  • CUse the image inspection and redaction actions of the DLP API to redact PII from the images
  • DUse the generalization and bucketing actions of the DLP API solution to redact PII from the texts

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    14% (4)
  • C
    72% (21)
  • D
    10% (3)

Explanation

The concern is PII appearing in images (pictures of documents) shared by customers. Cloud DLP's image inspection and redaction features can detect PII within images and redact (blur or mask) those regions before the image is stored, preserving the non-PII portions of the chat record for trend analysis. This maintains data utility while protecting sensitive information. Option A (Cloud KMS encryption) only controls who can decrypt - it doesn't remove PII from the data. Option B (Object Lifecycle Management) would delete the records entirely, destroying data utility. Option D (generalization/bucketing) applies to structured text data, not images - it cannot process pixel-based PII in photos.

Topics

#Data Loss Prevention (DLP)#PII Redaction#Image Processing#Data Protection

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice