GCP Professional Cloud Security Engineer Practice Question
A U.S. healthcare technology company will deploy a new micro-services platform that stores electronic protected health information (ePHI) from federal agencies. The security team must ensure that the environment satisfies FedRAMP High and HIPAA controls, keeps all data inside U.S. regions, restricts Google support access to screened U.S. persons, and automatically applies and monitors required organization policy constraints whenever new Google Cloud projects are created. Which solution will best meet these needs while minimizing ongoing administrative effort?
Create an Assured Workloads environment using the FedRAMP High compliance regime in a U.S. locale and provision all Google Kubernetes Engine projects inside the resulting workload folder.
Apply the FedRAMP organization-policy template to each project through infrastructure-as-code pipelines and store data in the multi-region us location.
Deploy the services on Cloud Run in projects labeled as HIPAA, rely on Cloud Support data avoidance, and manage location restrictions manually when resources are created.
Surround the projects with VPC Service Controls, enable Access Transparency and Access Approval, and add a gcp.resourceLocations organization policy limiting resources to U.S. regions.
Creating an Assured Workloads environment for the FedRAMP High regime automatically sets up a dedicated folder that:
Restricts resource creation to permitted U.S. regions, fulfilling data-residency and sovereignty requirements.
Applies a pre-defined bundle of organization policy constraints (for example, prohibiting external IPs and enforcing CMEK) and continuously monitors them for violations, eliminating the need to maintain custom policy code for each new project.
Enforces Google personnel controls so that only screened U.S. persons can access customer content or configurations, which is mandatory for FedRAMP High and helps meet HIPAA support requirements. The other options require manual policy management, do not address personnel restrictions, or rely on controls (such as VPC Service Controls or resource labels) that do not, by themselves, provide the comprehensive compliance coverage and automated enforcement that Assured Workloads delivers.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Assured Workloads and how does it help with compliance requirements?
Open an interactive chat with Bash
What are FedRAMP High compliance requirements?
Open an interactive chat with Bash
How does organization policy in Google Cloud work and why is it important?
Open an interactive chat with Bash
What is FedRAMP High compliance?
Open an interactive chat with Bash
How does Assured Workloads help meet HIPAA controls?
Open an interactive chat with Bash
What are organization policy constraints in GCP?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Supporting compliance requirements
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .