Google Professional Cloud Security Engineer Question 484
Select 2Google Cloud PlatformYour organization operates in a highly regulated industry and must comply with strict data residency requirements that mandate all sensitive customer data remain within a specific geographic region. Additionally, you need to ensure that Google Cloud administrators cannot access sensitive data without explicit approval from your organization. Which combination of Google Cloud features should you configure to meet these compliance requirements?
- A
Assured Workloads with the appropriate compliance regime for your region
- B
Access Approval to require explicit approval for Google Cloud administrator access
- C
Access Transparency to monitor Google Cloud administrator actions
- D
Data Loss Prevention (DLP) to detect and redact sensitive data
- E
Cloud Armor to protect against DDoS attacks
Show answer and explanation
Correct answers: A, B
Explanation
To meet the data residency and compliance requirements, Assured Workloads enforces regionalization of data and services, ensuring data remains in the required geographic location. Furthermore, Access Approval adds an additional layer of control by requiring explicit approval for any Google Cloud administrator access, helping to maintain compliance and security in regulated industries. Access Transparency, while useful for auditing, does not enforce controls, and other options like DLP and Cloud Armor address different aspects of security unrelated to this specific compliance scenario.
- A. Correct.
Assured Workloads help organizations meet compliance requirements by enforcing data residency, regionalization of services, and other regulatory controls specific to regions and industries.
- B. Correct.
Access Approval ensures that Google Cloud administrators cannot access customer data without explicit approval, which is critical for maintaining compliance in regulated environments.
- C. Incorrect.
Access Transparency provides visibility into Google Cloud administrator actions but does not prevent access or enforce compliance directly.
- D. Incorrect.
Data Loss Prevention (DLP) is used for identifying and managing sensitive data but does not enforce data residency or control administrator access.
- E. Incorrect.
Cloud Armor is a security service for protecting applications from DDoS attacks and is not related to compliance or data residency mandates.