GCP Professional Cloud Security Engineer Practice Question

An agency supporting U.S. federal customers must run a FedRAMP Moderate-authorized workload on Google Cloud. The application uses Compute Engine and Cloud SQL, and the security team requires: 1) resources restricted to U.S. locations, 2) enforcement that only Google personnel with U.S. citizenship may access the environment, 3) customer-managed encryption keys, and 4) an auditable, just-in-time approval flow whenever Google support needs to access data. Which Google Cloud design satisfies all requirements?

  • Use Cloud Armor to allow only U.S. IP addresses, store encryption keys in Cloud HSM, and enable Data Access audit logging for all services.

  • Apply a resourceLocations Organization Policy limiting creation to us-* regions, require customer-supplied encryption keys (CSEK), and depend solely on Cloud Audit Logs for provider access visibility.

  • Create an Assured Workloads FedRAMP environment for the projects, protect all data with CMEK keys in Cloud KMS, and enable both Access Approval and Access Transparency.

  • Place all resources in a VPC secured by VPC Service Controls, restrict service accounts with Organization Policy, and rely on default Google-managed encryption keys.

GCP Professional Cloud Security Engineer
Supporting compliance requirements
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot