Google Professional Cloud DevOps Engineer exam dumps

Google Professional Cloud DevOps Engineer practice question 129 of 268

Professional Cloud DevOps Engineer. Associate level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud DevOps Engineer Question 129

Select 3Google Cloud Platform

Your organization is building a healthcare application on Google Cloud Platform that processes and stores protected health information (PHI). To comply with regulatory requirements, you need to ensure secure handling of PHI while minimizing operational overhead. Which of the following actions should you take?

  1. A

    Use Cloud Storage with Object Versioning enabled to store PHI and ensure data integrity.

  2. B

    Encrypt PHI data at rest using Customer-Managed Encryption Keys (CMEK) and enforce access controls using IAM policies.

  3. C

    Implement a Virtual Private Cloud (VPC) Service Controls perimeter to restrict access to sensitive data.

  4. D

    Ensure PHI data is anonymized before it is processed in your application.

  5. E

    Store PHI data in an unencrypted BigQuery dataset for faster analytics processing.

Show answer and explanation

Correct answers: B, C, D

Explanation

Handling sensitive data such as PHI requires adhering to strict security and privacy practices to comply with regulations like HIPAA. Encrypting data at rest with CMEK, restricting access using VPC Service Controls, and anonymizing PHI before processing are essential steps to mitigate risks and ensure compliance. Object Versioning is useful for data integrity but does not address PHI-specific requirements, and storing PHI in an unencrypted format is a violation of best practices and regulatory standards.

  • A. Incorrect.

    While Object Versioning can ensure data integrity by preserving all versions of an object, it does not address specific regulatory requirements for handling PHI, such as encryption and access control.

  • B. Correct.

    Encrypting PHI at rest with Customer-Managed Encryption Keys (CMEK) ensures that the organization retains control over encryption keys, a best practice for regulatory compliance. IAM policies further restrict access to authorized users only.

  • C. Correct.

    VPC Service Controls provide an additional layer of security by creating a service perimeter to protect sensitive data from unauthorized access, which is crucial for handling PHI.

  • D. Correct.

    Anonymization of PHI before processing is a key practice to reduce the risk of exposing sensitive information and is often required by regulations such as HIPAA.

  • E. Incorrect.

    Storing PHI in an unencrypted BigQuery dataset is not compliant with regulatory standards and exposes sensitive data to significant security risks.

Timed practice exam

Take a Google Professional Cloud DevOps Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam