🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 52 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your organization runs hundreds of Google Cloud projects for different product teams worldwide. A subset of these projects process U.S. patient records and must be included in an upcoming HIPAA audit. The compliance team needs an auditable way to define the exact Google Cloud resources that fall under the HIPAA scope, apply stronger encryption and network controls to them only, and prevent other unrelated projects from inheriting those constraints. Which design best meets these goals while minimizing operational overhead?

  • Enable Access Transparency organization-wide so auditors can filter provider access logs to identify the projects that handled HIPAA data.

  • Place all projects in a single Shared VPC and rely on subnet-level firewall rules to identify and secure HIPAA traffic when needed.

  • Apply a hipaa=true label to all resources that process protected health information and use Cloud Asset Inventory queries during the audit to demonstrate scope.

  • Create a dedicated "HIPAA" folder under the organization, move every project that stores ePHI into it, and attach HIPAA-specific Organization Policies and hierarchical firewall rules to that folder.

GCP Professional Cloud Security Engineer
Supporting compliance requirements
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot