Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A financial enterprise stores regulated transaction records in Cloud Storage. Compliance mandates require that:
Which storage configuration strategy should the cloud architect implement to meet these requirements?
Set a Soft Delete retention duration of seven years on the bucket, and disable the Soft Delete policy at the project level whenever legal holds must be released.
Configure a bucket retention policy of seven years, permanently lock the policy with Bucket Lock, and apply individual object legal holds for records under active audit.
Enable Object Versioning with an Object Lifecycle Management rule to expire noncurrent versions after seven years, and enforce IAM Deny policies on storage.objects.delete for audited files.
Store records in BigLake Iceberg tables using Customer-Managed Encryption Keys (CMEK), and revoke KMS key access permissions during active audit holds.
Set a Soft Delete retention duration of seven years on the bucket, and disable the Soft Delete policy at the project level whenever legal holds must be released.
Configure a bucket retention policy of seven years, permanently lock the policy with Bucket Lock, and apply individual object legal holds for records under active audit.
Cloud Storage retention policies define the minimum duration that objects must remain unmodified and un-deleted within a bucket. When a retention policy is defined, any object uploaded to the bucket inherits this retention period. Bucket Lock allows an administrator to permanently lock the retention policy on a bucket, rendering the policy immutable and irreversible, even by project owners or Google Cloud administrators, fulfilling strict Write-Once-Read-Many (WORM) compliance standards.
This architecture directly fulfills both regulatory WORM standards and flexible eDiscovery legal hold requirements using native Cloud Storage governance primitives without custom scripts or complex IAM architectures.
Enable Object Versioning with an Object Lifecycle Management rule to expire noncurrent versions after seven years, and enforce IAM Deny policies on storage.objects.delete for audited files.
Store records in BigLake Iceberg tables using Customer-Managed Encryption Keys (CMEK), and revoke KMS key access permissions during active audit holds.