Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An organization is preparing for a PCI-DSS compliance audit of its cloud workloads. The security team discovers that cardholder data, including Primary Account Numbers (PAN), is mixed with non-regulated operational data across multiple BigQuery datasets and Compute Engine workloads.
To reduce the compliance audit footprint and establish a secure Cardholder Data Environment (CDE), the organization must:
Which strategy should the security engineer implement to achieve these objectives?
This architecture combines automated sensitive data discovery, organizational segregation, network perimeter enforcement, and fine-grained data governance to cleanly isolate and minimize the Cardholder Data Environment (CDE) scope under PCI-DSS.
CREDIT_CARD_NUMBER / PAN infoTypes. Integrating this with Data Catalog automatically applies business metadata tags and sensitivity classifications to datasets, tables, and columns.This solution directly satisfies the principle of least scope by separating regulated assets into dedicated container projects, applying strict perimeter isolation using VPC Service Controls, and cataloging all cardholder data automatically.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.