Google Professional Cloud DevOps Engineer exam dumps

Google Professional Cloud DevOps Engineer practice question 130 of 268

Professional Cloud DevOps Engineer. Associate level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud DevOps Engineer Question 130

Select 3Google Cloud Platform

Your organization is hosting a healthcare application on Google Cloud that processes and stores protected health information (PHI). As a Google Cloud DevOps Engineer, how should you ensure compliance with data privacy regulations while managing this workload?

  1. A

    Use Cloud Data Loss Prevention (DLP) to identify and redact sensitive information in logs and datasets.

  2. B

    Encrypt all PHI data at rest using Cloud Key Management Service (KMS) with customer-managed encryption keys.

  3. C

    Store PHI data in a public Cloud Storage bucket for easier access by authorized users.

  4. D

    Use Identity and Access Management (IAM) to enforce the principle of least privilege for accessing PHI data.

  5. E

    Disable logging for all services that interact with PHI to prevent accidental data exposure.

Show answer and explanation

Correct answers: A, B, D

Explanation

Handling sensitive data, such as PHI, in Google Cloud requires a combination of tools and best practices to ensure compliance with data privacy regulations. Cloud DLP helps identify and redact sensitive information, encryption with KMS secures data at rest, and IAM enforces strict access controls. Storing PHI in a public bucket or disabling logging are not compliant practices, as they increase the risk of data exposure and reduce auditability.

  • A. Correct.

    Cloud DLP is designed to identify, classify, and optionally redact sensitive information such as PHI. It helps ensure compliance with data privacy regulations by controlling data exposure.

  • B. Correct.

    Encrypting PHI data at rest with customer-managed encryption keys provides an additional layer of security and ensures compliance with regulations like HIPAA.

  • C. Incorrect.

    Storing PHI in a public Cloud Storage bucket is a poor practice as it exposes sensitive data to unauthorized access, violating data privacy regulations.

  • D. Correct.

    IAM enables you to enforce the principle of least privilege, ensuring that only authorized users have access to PHI data, which is critical for maintaining compliance.

  • E. Incorrect.

    Disabling logging for all services is not a recommended practice as it hinders troubleshooting and auditing. Instead, sensitive data within logs should be sanitized using tools like Cloud DLP.

Timed practice exam

Take a Google Professional Cloud DevOps Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam