GCP Professional Cloud Architect Practice Question
Your fintech platform runs multiple microservices on Google Cloud. A new audit requires the Cardholder Data Environment (CDE)-made up of a payment-processing service and its Cloud SQL for PostgreSQL instance-to comply with PCI DSS v4. The CDE must be strictly segmented from other workloads, permit only the minimum traffic required from the public front-end service, and retain immutable audit logs for at least one year. Which architecture best meets these requirements while keeping operational overhead low?
Create a new Kubernetes namespace for the payment service in the existing GKE cluster, apply NetworkPolicy rules, keep the same project and VPC, enable Cloud SQL IAM authentication, and rely on Cloud Logging's default 400-day retention.
Move the payment service and Cloud SQL instance to a dedicated project that uses its own standalone VPC; peer no networks, allow only HTTPS traffic from the front-end project through tight ingress/egress firewall rules, and export all Admin Activity and Data Access logs to a Cloud Storage bucket protected with Bucket Lock in a central audit project.
Keep all workloads in the current project, wrap the Cloud SQL instance with a VPC Service Controls perimeter, restrict external access using Cloud Armor IP allowlists, and export logs to a BigQuery dataset with a 400-day table expiration.
Deploy the payment service to Cloud Run in the current project but tag it with a PCI label; enforce access using IAM Conditions, and publish all logs to Pub/Sub for downstream processing by a SIEM.
Creating a completely separate Google Cloud project and VPC for the CDE provides the strongest PCI-recommended segmentation boundary: IAM policies, service-level quotas, and VPC-level firewall rules do not bleed into other workloads. Peering or Shared VPC is avoided, so only explicitly whitelisted ingress and egress rules allow payment traffic from the front-end project. Exporting all Cloud Audit Logs from the CDE project to a centrally managed Cloud Storage bucket that uses Bucket Lock makes the logs immutable for the mandated retention period. This design directly addresses PCI's network segmentation and tamper-evident logging controls while requiring minimal day-to-day management. The other options fail key controls: keeping everything in one project (or even one VPC) does not create a true CDE boundary, VPC Service Controls do not isolate network paths inside a VPC, per-namespace or label-based isolation is insufficient for PCI, and BigQuery/Pub Sub sinks without Bucket Lock cannot guarantee immutability.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is PCI DSS v4, and why is it important for fintech platforms?
Open an interactive chat with Bash
How does using a dedicated VPC enhance security for the CDE?
Open an interactive chat with Bash
What is Bucket Lock, and how does it ensure immutable audit logs?
Open an interactive chat with Bash
What is PCI DSS v4 compliance and why is it important?
Open an interactive chat with Bash
What is Bucket Lock in Google Cloud Storage and how does it make logs immutable?
Open an interactive chat with Bash
Why does segmenting workloads into separate projects and standalone VPCs improve security?
Open an interactive chat with Bash
GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .