GCP Professional Cloud Security Engineer Practice Question

A healthcare company runs a genomics-analysis pipeline on a managed instance group (MIG) of Compute Engine VMs (Debian 11, n1-standard-8). A regulator now requires that all protected health information (PHI) be encrypted not only at rest and in transit but also while it is processed in memory. The engineering team wants to meet this requirement without modifying the application code, does not want to run its own key-management software, and can tolerate up to 10 % additional CPU overhead. Audit logs for administrative actions must remain available. What should the team do?

  • Integrate an application library such as Google Tink to encrypt and decrypt all PHI in memory before and after every CPU operation.

  • Move the MIG's disks to CMEK-encrypted persistent disks and mount them on the existing n1-standard-8 instances.

  • Create a new instance template that enables Confidential compute, switch to a machine type that supports Confidential VMs (for example, n2d-standard-8), and recreate the MIG with that template.

  • Migrate the workload to Google Kubernetes Engine and enable Shielded GKE Nodes with Workload Identity.

GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot