Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A healthcare enterprise configures an Assured Workloads folder using the US Data Boundary for Healthcare and Life Sciences control package to maintain HIPAA compliance. An engineering team requires a Google Cloud service that is covered under Google Cloud's HIPAA Business Associate Agreement (BAA) and supports US data residency and CMEK, but is not included in the control package's default service list.
A cloud security engineer updates the gcp.restrictServiceUsage organization policy constraint on the folder to allow the service. Following this change, Assured Workloads continuous monitoring flags compliance violations on the modified resources.
What action should the security engineer take to resolve the continuous monitoring alerts while maintaining a compliant posture?
Assured Workloads continuous monitoring actively audits resources against the baseline requirements of the assigned compliance regime (such as HIPAA/HITRUST). When an administrator expands service availability by customizing the gcp.restrictServiceUsage organization policy constraint, Assured Workloads detects deviation from its preconfigured baseline and flags active compliance violations. Granting an exception in the Assured Workloads console acknowledges that the deviation was intentional, verified, and accepted by security administrators.
This approach directly satisfies the operational requirement to allow HIPAA-compliant services outside the default baseline while preserving active continuous monitoring and generating a documented compliance record.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.