🔥 40% Off Crucial Exams Memberships — Deal ends today!

11 minutes, 6 seconds remaining!

GCP Professional Cloud Security Engineer Practice Question

An online retailer is migrating its card-holder data environment (CDE) to Google Cloud and must prepare for a PCI DSS audit. Architects need to keep the CDE out of scope for non-PCI workloads yet still allow internal HTTP API calls from services running in other projects. Which design best achieves PCI scope reduction while keeping administration effort low?

  • Deploy CDE instances with public IP addresses in a separate VPC and rely on Cloud Armor policies to limit access to the IP ranges of non-PCI services.

  • Keep CDE and non-PCI workloads in distinct projects but interconnect the two VPCs with VPC Network Peering, using IAM Conditions to restrict which service accounts can initiate traffic.

  • Create a dedicated project that hosts its own standalone VPC for the CDE, place the project in a "PCI" folder, and expose required APIs through an Internal HTTP(S) Load Balancer or Private Service Connect; do not establish any VPC peering to other projects.

  • Attach every project, including the CDE, to a single organization-wide Shared VPC and use firewall rules to block all traffic except TCP 443 between CDE and non-PCI subnets.

GCP Professional Cloud Security Engineer
Supporting compliance requirements
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot