Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 489 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 489

Select 3Google Cloud Platform

Your organization operates in the healthcare industry and must comply with strict data residency and access transparency requirements. You have been asked to configure Google Cloud services to meet these compliance needs. Which combination of settings and tools should you use to ensure compliance?

  1. A

    Enable Assured Workloads and configure a compliance regime for your region.

  2. B

    Use Access Approval to require explicit approval for Cloud IAM role changes.

  3. C

    Implement organizational policies to enforce regionalization of data and services.

  4. D

    Enable Access Transparency logs to track Google support personnel access to your data.

  5. E

    Use Cloud Armor to protect against DDoS attacks and ensure compliance.

Show answer and explanation

Correct answers: A, C, D

Explanation

To meet compliance requirements for data residency and access transparency, you need to use Assured Workloads for compliance regimes, organizational policies to enforce regionalization of data, and Access Transparency to monitor support access to your data. These tools collectively address the regulatory needs of the healthcare industry as outlined in the scenario.

  • A. Correct.

    Enabling Assured Workloads allows you to configure compliance regimes (e.g., HIPAA, FedRAMP) and ensures that workloads meet data residency and other regulatory requirements.

  • B. Incorrect.

    Access Approval is used to control support access rather than IAM role changes. While it enhances security, it is not directly tied to the compliance requirements in this scenario.

  • C. Correct.

    Organizational policies can enforce regionalization to ensure data and services remain in specific locations, which is critical for meeting data residency requirements.

  • D. Correct.

    Access Transparency provides visibility into Google support personnel access, ensuring compliance with transparency and auditability requirements.

  • E. Incorrect.

    Cloud Armor is a security tool for protecting applications from DDoS attacks but is unrelated to compliance with data residency or transparency requirements.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam