🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 50 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

A Canadian healthcare provider is migrating a diagnostics imaging archive (over 500 TB) to Google Cloud. Regulatory guidance mandates that:

  • All patient data must remain only within Canada at rest.
  • Encryption keys must be created, rotated, and deleted exclusively by the provider's security team.
    The archive will be accessed by Compute Engine instances running in northamerica-northeast1 (Montréal).

Which solution best satisfies both the data-at-rest residency and encryption requirements while minimizing future compliance risk?

  • Create a regional Cloud Storage bucket in northamerica-northeast1, protect it with a Cloud KMS CMEK stored in the same region, and enforce an organization policy that restricts resource locations to Canadian regions only.

  • Create a dual-region NAM4 bucket to gain higher durability, use default Google-managed encryption, and rely on VPC Service Controls to restrict data egress.

  • Create a regional Cloud Storage bucket in us-central1, encrypt it with a CMEK in a global key ring, and limit access to the bucket using IAM Conditions.

  • Create a multi-region Cloud Storage bucket in northamerica, encrypt it with Google-managed keys, and access it from Compute Engine.

GCP Professional Cloud Security Engineer
Supporting compliance requirements
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot