professional-cloud-data-engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
Your financial enterprise processes sensitive customer transaction records subject to strict European Union data residency and sovereignty regulations. The compliance policy mandates the following requirements:
europe-west3 (Frankfurt) region.europe-west3, while maintaining resilience against potential single-zone capacity constraints or outages.How should you configure the architecture to enforce compliance and data sovereignty while ensuring job execution resilience?
Create Cloud Storage buckets in europe-west3 and generate Cloud KMS keys in the europe multi-region location. Launch the Dataflow job specifying --region=europe-west3 and an explicit --zone=europe-west3-a parameter.
Create Cloud Storage buckets in europe-west3 and provision Cloud KMS keys in the global location. Launch the Dataflow pipeline specifying --region=europe-west3 and configure Dataflow workers to execute in europe-west1.
Create Cloud Storage buckets in europe-west3 and generate Cloud KMS keys in europe-west3. Enforce the gcp.restrictNonCmekServices constraint, and execute Dataflow jobs by setting --zone=europe-west3-b while omitting the --region flag.
Create Cloud Storage buckets and a Cloud KMS key ring with keys in the regional location europe-west3. Enforce the gcp.resourceLocations organization policy for europe-west3. Launch the Dataflow job specifying --region=europe-west3 without setting the --zone parameter.
Create Cloud Storage buckets in europe-west3 and generate Cloud KMS keys in the europe multi-region location. Launch the Dataflow job specifying --region=europe-west3 and an explicit --zone=europe-west3-a parameter.
Create Cloud Storage buckets in europe-west3 and provision Cloud KMS keys in the global location. Launch the Dataflow pipeline specifying --region=europe-west3 and configure Dataflow workers to execute in europe-west1.
Create Cloud Storage buckets in europe-west3 and generate Cloud KMS keys in europe-west3. Enforce the gcp.restrictNonCmekServices constraint, and execute Dataflow jobs by setting --zone=europe-west3-b while omitting the --region flag.
Create Cloud Storage buckets and a Cloud KMS key ring with keys in the regional location europe-west3. Enforce the gcp.resourceLocations organization policy for europe-west3. Launch the Dataflow job specifying --region=europe-west3 without setting the --zone parameter.
This architecture establishes strict regional data residency and governance controls using location-bound Cloud KMS keys, organization policy constraints, and Cloud Dataflow regional job execution.
europe-west3 satisfies data sovereignty and complies with CMEK location constraints.gcp.resourceLocations organization policy constraint restricted to europe-west3 guarantees that no storage, compute, or cryptographic resources can be provisioned outside the authorized boundary.--region=europe-west3 and omitting the --zone flag directs Dataflow to route worker VMs dynamically across any healthy zone strictly within europe-west3 based on availability, ensuring resilience against zonal failures while maintaining geographic containment.europe-west3.europe-west3 regional boundary.This approach directly satisfies EU regulatory data boundaries and CMEK requirements while leveraging regional elasticity for fault tolerance.