🔥 40% Off Crucial Exams Memberships — Deal ends today!

45 minutes, 4 seconds remaining!

GCP Professional Cloud Architect Practice Question

A healthcare provider must migrate a latency-sensitive microservices workload to Google Kubernetes Engine in a new project. The services will store protected health information (PHI) in Cloud Storage. Compliance rules require that:

  • encryption at rest must use keys controlled and rotated by the provider,
  • all network traffic between the on-premises data center and GKE must be encrypted,
  • the link must sustain at least 5 Gbps while keeping operational overhead low. Which architecture satisfies these requirements?
  • Configure Cloud Storage buckets with a customer-managed key in Cloud KMS and establish a Dedicated Interconnect circuit with HA VPN tunnels running over the Interconnect VLAN attachments.

  • Encrypt objects client-side with self-managed keys before uploading to Cloud Storage and use standalone Cloud VPN tunnels over the public internet for connectivity.

  • Use Cloud Storage buckets with Google-managed default encryption and connect the data center with a Dedicated Interconnect circuit that carries traffic in clear text.

  • Enable bucket-level default CMEK encryption and connect the data center via Partner Interconnect without any additional encryption because the circuit is private.

GCP Professional Cloud Architect
Designing and planning a cloud solution architecture
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot