Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise is deploying an AI agent solution built on the Gemini platform on Google Cloud. The architecture processes real-time user prompts, retrieves context from backend storage, and persists conversation history and model outputs.
The security team mandates the following compliance and data governance requirements:
europe-west1 region and be prevented from crossing virtual network boundaries.Which combination of security controls should the security engineer implement?
This architecture combines Sensitive Data Protection (Cloud DLP) regional endpoints, VPC Service Controls, Cloud KMS, and Organization Policy Service constraints to establish end-to-end data governance, strict data residency, and encryption for AI workloads.
content.deidentify API method of Cloud DLP inspects and de-identifies prompt strings and model responses in real time before data reaches persistent backend storage.dlp.europe-west1.rep.googleapis.com ensures that TLS sessions terminate inside europe-west1, guaranteeing that data at rest, in use, and in transit never leaves the specified region. Enforcing constraints/gcp.restrictEndpointUsage prevents client calls from accidentally routing to global endpoints.constraints/gcp.resourceLocations limits resource provisioning strictly to europe-west1 across all projects.europe-west1 wrap local data encryption keys (DEKs) ensuring full customer control over encryption at rest.content methods sanitizes generative AI inputs and outputs before storage.Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.