Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise is deploying a financial analytics platform on Google Cloud using Compute Engine virtual machines and Cloud Storage. The organization is preparing for an independent SOC 2 Type II compliance audit and needs to distinguish between security controls provided directly by Google Cloud versus controls that the enterprise's cloud architects must configure and operate.
According to the shared responsibility model, which security control is fully managed by Google Cloud and verified via Google's third-party audit reports?
Identity and Access Management (IAM) role assignments and dataset access control policies
Customer data classification, data retention policies, and application-level logging configuration
Physical access security to data center facilities and hardware-level boot integrity verification
Operating system patch management and security baseline configurations for Compute Engine guest instances
Identity and Access Management (IAM) role assignments and dataset access control policies
Customer data classification, data retention policies, and application-level logging configuration
Physical access security to data center facilities and hardware-level boot integrity verification
In cloud computing's shared responsibility model, the cloud service provider (Google Cloud) is entirely responsible for the security of the cloud. This encompasses the physical data centers, underlying hardware provenance, server boards, custom security chips (such as Titan), and low-level hypervisor systems that host multi-tenant cloud services.
For compliance audits like SOC 2 Type II, ISO/IEC 27001, or PCI DSS, customers do not have direct physical access to Google data centers to perform inspections themselves. Instead, Google engages independent third-party auditors who evaluate these physical and foundational hardware controls annually:
Physical data center security and hardware cryptographic verification are strictly the domain of the cloud provider. Cloud architects cannot install physical barriers or modify Google's server firmware, making this an inherited control fully satisfied through Google's compliance documentation.
Operating system patch management and security baseline configurations for Compute Engine guest instances