🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 0 minute remaining!

GCP Professional Cloud Security Engineer Practice Question

Your organization runs an e-commerce front-end in project "web-prod." To achieve PCI-DSS compliance, the payment-processor microservice must reside in a Cardholder Data Environment (CDE) that is strictly isolated from all other workloads. The front-end still needs a private, low-latency way to invoke the payment service, and a centralized logging project must aggregate logs from both environments without creating any additional network path between them. Which design best satisfies these requirements?

  • Run the payment service in the web-prod project but in a different Kubernetes namespace, enforce Kubernetes Network Policies for segmentation, and forward logs to the centralized logging project.

  • Place the payment service in a separate subnet of the Shared VPC used by web-prod, restrict access with firewall tags, and export logs to the centralized logging project.

  • Host the payment service in a dedicated VPC and peer it with the web-prod VPC, limiting traffic by exchanging only required custom routes, and send logs to the centralized logging project.

  • Deploy the payment service in a separate project with its own VPC network, publish it through Private Service Connect, grant the web-prod project consumer access to the PSC endpoint, and export logs from both projects to the centralized logging project via log sinks.

GCP Professional Cloud Security Engineer
Supporting compliance requirements
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot