🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 50 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

An American public safety agency is moving a records-management workload to Google Cloud. To satisfy CJIS, it must 1) keep all data in U.S. locations, 2) ensure that any Google support access is limited to U.S. citizens who have passed CJIS background checks, and 3) have every new project automatically inherit the same controls. Which approach satisfies these requirements with the least ongoing operational effort?

  • Block non-U.S. IP addresses with Cloud Armor, use CMEK with U.S.-hosted keys, and purchase a premium support plan that guarantees response from U.S.-based staff.

  • Deploy the application only in us-central1 and us-east4, enable Access Transparency logs, and place the projects inside a VPC Service Controls perimeter.

  • Configure an organization policy that restricts resource locations to U.S. regions, enable Access Approval on all projects, and manually verify CJIS eligibility for each Google support request.

  • Create an Assured Workloads environment with the CJIS compliance regime in a dedicated folder and provision all current and future projects inside that environment.

GCP Professional Cloud Security Engineer
Supporting compliance requirements
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot