🔥 40% Off Crucial Exams Memberships — Deal ends today!

44 minutes, 40 seconds remaining!

GCP Professional Cloud Security Engineer Practice Question

Your company is creating a new folder called "Banking" under the organization root to host services that will store and process personal data of EU residents. GDPR and internal policy require that all customer data, system metadata, and any access by Google personnel stay strictly within EU regions. Security leadership wants a single preventive control that automatically applies to every new project in the folder while still giving developers freedom to choose any EU region. Which solution best satisfies the requirement with the least ongoing operational effort?

  • Mandate that every project stores data using CMEK keys in an EU key ring and locates Cloud Storage buckets in the EU multi-region, verified periodically with Security Command Center.

  • Create an Assured Workloads environment in the Banking folder using the "EU Regions and Support" compliance regime, and deploy all projects inside that environment.

  • Place all Banking projects inside a VPC Service Controls perimeter that blocks egress to IP ranges located outside the EU.

  • Apply the organization-policy constraint constraints/gcp.resourceLocations to the Banking folder, allowing only specific EU regions, and enable Access Transparency for auditing.

GCP Professional Cloud Security Engineer
Supporting compliance requirements
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot