GCP Professional Cloud Security Engineer Practice Question

A global retailer runs more than 100 Google Cloud projects in a single organization. Only a subset of workloads store or process cardholder data and therefore fall under PCI DSS scope. The security team must 1) isolate these in-scope resources from all other workloads, 2) attach stricter Organization Policy constraints and IAM limits only to the in-scope environment, and 3) keep the solution simple to administer over time. Which design best meets these objectives?

  • Create a dedicated "pci" folder beneath the organization root, move or create all PCI-related projects inside it, and apply the required Organization Policy constraints and IAM restrictions at that folder level.

  • Keep all projects as they are but create a separate "pci-vpc" network in each one, protect it with hierarchical firewall rules, and track scoped resources in a spreadsheet.

  • Add a "pci=true" label to every resource that handles cardholder data and rely on Cloud Asset Inventory queries and label-based VPC Service Controls to enforce PCI controls.

  • Apply the stricter Organization Policy constraints at the organization node and override them in non-PCI projects that should remain out of scope.

GCP Professional Cloud Security Engineer
Supporting compliance requirements
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot