GCP Professional Data Engineer Practice Question

Your organization is subject to GDPR and must guarantee that any resource storing or processing customer PII is deployed only in EU regions (europe-west* and europe-central2). Multiple engineering teams use automated Terraform pipelines that create new Cloud Storage buckets, BigQuery datasets, and Dataflow jobs in their projects. To enforce the regional restriction on every current and future project that hosts PII workloads, while letting unrelated projects remain unrestricted, what should you do?

  • Place the PII projects in a VPC Service Controls perimeter that allows access only from EU IP address ranges.

  • Create a folder for all projects that process customer PII and attach an organization-policy with the gcp.resourceLocations constraint set to allow only EU regions.

  • Build a custom IAM role that removes permissions to create resources in non-EU regions and assign it to all developers in the affected projects.

  • Enable Cloud Asset Inventory feeds on the organization and deploy a Cloud Function that deletes any newly detected resource located outside the EU.

GCP Professional Data Engineer
Designing data processing systems
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot