Google Professional Cloud Security Engineer Question 491
Select 3Google Cloud PlatformYour company is planning to migrate its workloads to Google Cloud, but it must comply with GDPR (General Data Protection Regulation) requirements. As a Professional Cloud Security Engineer, what actions should you take to determine the Google Cloud environment in scope for regulatory compliance?
- A
Identify all Google Cloud regions where customer data will be stored or processed.
- B
Evaluate the compliance certifications and attestations of Google Cloud services to confirm GDPR alignment.
- C
Ensure that all services used are only available in European Google Cloud regions.
- D
Review the organization's data classification to determine which data is subject to GDPR.
- E
Enable default data encryption for all Google Cloud services.
Show answer and explanation
Correct answers: A, B, D
Explanation
Determining the Google Cloud environment in scope for regulatory compliance involves understanding where customer data is stored or processed, ensuring that Google Cloud services meet the required compliance certifications, and identifying which data is subject to the regulation. This approach ensures that the necessary steps are taken to remain compliant while leveraging Google Cloud services.
- A. Correct.
Correct: Identifying the regions where data is stored or processed is essential for determining the scope of compliance, especially for regulations like GDPR that have data residency requirements.
- B. Correct.
Correct: Evaluating Google Cloud’s compliance certifications ensures that the services you plan to use meet GDPR requirements.
- C. Incorrect.
Incorrect: While GDPR emphasizes data protection, it does not mandate that all data must remain within European regions. Data can reside outside Europe if appropriate measures, such as Standard Contractual Clauses, are in place.
- D. Correct.
Correct: Reviewing data classification is critical to identify which data falls under GDPR and determine the compliance scope.
- E. Incorrect.
Incorrect: While data encryption is a best practice for security, it alone does not determine the Google Cloud environment in scope for regulatory compliance.