Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise financial organization is preparing for an upcoming regulatory audit. The external compliance auditors have requested formal evidence of the underlying cloud provider's security posture, specifically requiring:
Which Google Cloud resource should the cloud architect leverage to acquire these third-party compliance reports and attestation letters?
Access Google Cloud Artifact / Compliance Reports Manager via the Compliance Resource Center to download third-party audit reports, certifications, and bridge letters directly under NDA
Deploy Artifact Registry to store and sign container images with Binary Authorization attestations
Configure Security Command Center to export vulnerability findings and compliance posture scores directly to the auditors
Query Cloud Audit Logs in Cloud Logging to extract administrator data access and system event entries for the audit period
Access Google Cloud Artifact / Compliance Reports Manager via the Compliance Resource Center to download third-party audit reports, certifications, and bridge letters directly under NDA
Google Cloud Artifact (and the Compliance Reports Manager within the Compliance Resource Center) is Google Cloud's centralized portal for customers to access and download security and compliance documentation. It provides direct, self-service access to third-party audit reports, certifications, letters of attestation, and bridge letters that validate Google Cloud's shared responsibility posture.
Under the cloud shared responsibility model, customers inherit Google Cloud's baseline security controls. To satisfy regulatory auditors regarding infrastructure controls that customers do not manage directly, organizations must present Google's independent third-party audit reports and attestations obtained through the Compliance Resource Center.
Deploy Artifact Registry to store and sign container images with Binary Authorization attestations
Configure Security Command Center to export vulnerability findings and compliance posture scores directly to the auditors
Query Cloud Audit Logs in Cloud Logging to extract administrator data access and system event entries for the audit period