GCP Professional Cloud Architect Practice Question
Your retail startup is moving to Google Cloud. The payment processing microservice stores cardholder data and must be scoped as the PCI-DSS Cardholder Data Environment (CDE). Marketing dashboards and recommendation engines run in separate projects and need to call the payment API. Which design most effectively meets PCI isolation requirements while still permitting the other workloads to invoke the API?
Deploy the payment microservice and all other workloads in one project and VPC, using firewall rules and Cloud Armor policies to restrict access to cardholder data.
Host the payment microservice in a dedicated project with its own VPC and publish the service internally via Private Service Connect endpoints that are granted only to approved service accounts in the other projects.
Place the payment service in a dedicated subnet inside the same VPC as marketing workloads, surround that subnet with VPC Service Controls, and expose the API through an internal HTTP(S) load balancer.
Create a Shared VPC host project and attach both payment and marketing service projects to it, isolating the CDE in a separate subnet protected by firewall rules.
PCI DSS guidance recommends isolating the Cardholder Data Environment in its own security domain. In Google Cloud the cleanest boundary is a dedicated project that uses its own VPC network. Exposing the payment service only through Private Service Connect keeps traffic on Google's internal network and avoids establishing broad network-layer connectivity such as VPC peering or shared subnets. The remaining options leave the CDE in the same project or VPC as non-CDE workloads, or rely solely on firewall rules or Service Controls, which do not provide the strong administrative and network isolation that PCI-DSS expects.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is PCI-DSS and why is it important for payment systems?
Open an interactive chat with Bash
How does Private Service Connect ensure secure communication in Google Cloud?
Open an interactive chat with Bash
How does a dedicated project with its own VPC improve PCI isolation and security?
Open an interactive chat with Bash
What is PCI DSS and why does it require data isolation?
Open an interactive chat with Bash
What is Private Service Connect in Google Cloud?
Open an interactive chat with Bash
How does using a dedicated project and VPC provide stronger isolation compared to Shared VPCs or subnets?
Open an interactive chat with Bash
GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .