Professional Cloud Architect · Free Practice Question Hard

Question 38

Your organization stores sensitive customer data in Cloud Storage. You have been asked to design a solution that both prevents unauthorized data access and ensures regulatory compliance. Which of the following approaches would be the most appropriate?

  • A

    Use VPC Service Controls to isolate Cloud Storage.

  • B

    Encrypt data using customer-managed encryption keys (CMEK) and enforce fine-grained access control with Identity and Access Management (IAM).

  • C

    Implement Cloud Identity-Aware Proxy (IAP) to control access to Cloud Storage.

  • D

    Use Cloud Audit Logs to monitor access to Cloud Storage.

Reveal correct answer

Correct answer: B

A.

While VPC Service Controls can provide additional security measures, they are primarily used for preventing data exfiltration from Google Cloud services. They do not directly handle encryption or access management within Cloud Storage.

B.

By using CMEK, you can control the encryption and decryption keys. With IAM, you can enforce fine-grained access control, ensuring that only authorized entities have access to specific resources.

C.

While IAP is an effective tool for controlling access to applications deployed on Google Cloud, it's not specifically designed to secure data stored in Cloud Storage.

D.

While Cloud Audit Logs can provide valuable information on who did what, when, and where, they are more about visibility and accountability, and do not prevent unauthorized access to Cloud Storage.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need