🔥 40% Off Crucial Exams Memberships — Deal ends today!

44 minutes, 43 seconds remaining!

GCP Professional Cloud Security Engineer Practice Question

A fintech company runs several non-PCI workloads in a Google Cloud project. You must deploy a new GKE-based payment-processing microservice that will form the PCI-DSS Cardholder Data Environment (CDE). Requirements:

  • Isolate all CDE resources from existing workloads.
  • Allow the microservice to call an internal Cloud Run API only-no other projects or internet egress.
  • Minimize ongoing operational effort. Which design best satisfies these constraints?
  • Keep the microservice in the existing project, place it in a separate GKE namespace, apply Kubernetes NetworkPolicies to allow only egress to the Cloud Run API, and protect the service with Cloud Armor.

  • In the existing project, create a standalone VPC for the microservice, disable VPC peering, and rely solely on custom firewall rules to prevent traffic to other networks.

  • Create a new project under a PCI-specific folder, attach it as a service project to a dedicated Shared VPC host for PCI workloads, allow only required traffic to the Cloud Run service via firewall rules, and place both projects in a VPC Service Controls perimeter to mitigate cross-project and internet egress.

  • Enable Private Service Connect so the GKE cluster can privately invoke the Cloud Run API, use IAM conditions to limit access, and deploy all components in the same project and VPC.

GCP Professional Cloud Security Engineer
Supporting compliance requirements
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot