🔥 40% Off Crucial Exams Memberships — Deal ends today!

10 minutes, 11 seconds remaining!

GCP Professional Cloud Security Engineer Practice Question

Your financial services company is building a payment-processing platform on Google Cloud. Corporate policy stipulates that all cardholder data must (1) remain only in United States regions or the US multi-region and (2) be technically prevented from being copied to projects or Cloud Storage buckets that are outside the designated cardholder data environment (CDE). You have placed every in-scope project under a dedicated "pci" folder. Which approach best meets both requirements with minimal ongoing operational effort?

  • Enable customer-managed encryption keys (CMEK) for all Cloud Storage buckets in the pci folder and add IAM Deny policies that block the storage.objects.copy permission when the destination project is not tagged as pci.

  • Configure all CDE VPC networks with Private Google Access and Cloud NAT only, and apply firewall rules that block egress to public IP ranges so data cannot leave the VPC.

  • Activate Access Transparency and Access Approval for the pci folder and export all Cloud Audit Logs to a centralized logging project to monitor for unauthorized copies of data.

  • Apply an organization policy in the pci folder that allows only US regions and the us multi-region with the constraints/gcp.resourceLocations constraint, then create a VPC Service Controls perimeter around the folder and add (or rely on the default) egress restrictions to block access to resources outside the perimeter.

GCP Professional Cloud Security Engineer
Supporting compliance requirements
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot