GCP Professional Cloud Security Engineer Practice Question

An insurance company subject to GDPR will run nightly Spark jobs against customer PII. Corporate policy states that (1) data must never leave the European Union, (2) data at rest must be encrypted with customer-managed keys, and (3) compute instances must have no direct Internet exposure. You need to design the processing environment on Google Cloud with minimal operational overhead. Which solution satisfies every control?

  • Build a private GKE cluster in europe-west1, mount a multi-region EU Cloud Storage bucket with default encryption, and allow nodes to access package repositories via their own external IP addresses.

  • Deploy a managed instance group of Compute Engine VMs with public IPs in us-central1, store data in a multi-region EU Cloud Storage bucket encrypted with Google-managed keys, and block unwanted traffic using firewall rules.

  • Create an internal-only Dataproc cluster in europe-west3, store all data in a regional Cloud Storage bucket in europe-west3 protected by a Cloud KMS CMEK key, apply the gcp.resourceLocations organization policy to EU regions, and provide outbound Internet access through Cloud NAT.

  • Run Cloud Dataflow jobs in us-west1, keep datasets in a BigQuery US multi-region dataset encrypted with CMEK, and isolate projects with VPC Service Controls.

GCP Professional Cloud Security Engineer
Supporting compliance requirements
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot