🔥 40% Off Crucial Exams Memberships — Deal ends today!

10 minutes, 59 seconds remaining!

GCP Professional Cloud Security Engineer Practice Question

A pan-European fintech is migrating its card-processing platform to Google Cloud. The legal team mandates the following:

  1. All customer data and metadata must remain within the European Economic Area to comply with GDPR data-sovereignty clauses.
  2. Persistent disks and Cloud Storage objects must be encrypted with keys that the company fully controls.
  3. Google support personnel may access the environment only after explicit, just-in-time approval and all such access must be auditable.

The organization root node for Google Cloud is already in place. Which approach best satisfies all requirements while keeping ongoing operational effort low?

  • Apply the constraints/gcp.resourceLocations Organization Policy to allow only europe-west1 and europe-west4, create Cloud KMS keys in europe-west1 for CMEK, enable Access Approval and Access Transparency, and use VPC Service Controls to build a perimeter around the projects.

  • Create an Assured Workloads environment using the "EU Regions and Support" regime, place all projects for the platform inside its folder, enforce CMEK by setting the constraints/compute.requireCmekForBootDisk and constraints/storage.uniformBucketLevelAccess Organization Policies, and enable both Access Approval and Access Transparency on those projects.

  • Use Cloud External Key Manager (EKM) with an HSM located in Paris to hold encryption keys, configure a service perimeter with Private Google Access only, and rely solely on Access Transparency for auditing provider access.

  • Deploy all resources manually in europe-west1 and europe-north1 regions, rely on Google-managed encryption keys, configure VPC Firewalls to block egress to non-EU IP ranges, and export Cloud Audit Logs to BigQuery for retention.

GCP Professional Cloud Security Engineer
Supporting compliance requirements
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot