🔥 40% Off Crucial Exams Memberships — Deal ends today!

3 hours, 1 minute remaining!

GCP Professional Cloud Security Engineer Practice Question

Your fintech company is migrating a PCI DSS-regulated platform also subject to GDPR. Cardholder data must stay only in the Frankfurt region (europe-west3). Policy requires Google staff access to projects only with explicit, time-bound security-team approval and full audit logs. You must stop cross-project data exfiltration from the PCI environment without managing many firewall rules. Which Google Cloud design meets all requirements with minimal operational overhead?

  • Store all cardholder data in a Cloud Storage Multi-Region EU bucket protected with CMEK, turn on Access Transparency, and rely on custom VPC firewall egress rules to limit data flows.

  • Tokenize card data with Cloud DLP, keep workloads in europe-west3 using default project settings, and require support engineers to connect through Identity-Aware Proxy for troubleshooting access.

  • Host databases on Cloud SQL encrypted with customer-supplied keys stored in us-central1, disable external IPs on all VMs via organization policy, and depend on Cloud Audit Logs alone to monitor provider access.

  • Create an EU Assured Workloads environment, apply the gcp.resourceLocations organization policy to allow only europe-west3, enable Access Approval, and place all PCI projects inside a VPC Service Controls perimeter.

GCP Professional Cloud Security Engineer
Supporting compliance requirements
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot