Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An organization is migrating its financial transaction processing workloads to Google Cloud and preparing for an upcoming PCI DSS and SOC 2 Type II compliance audit. The target environment includes:
To establish the compliance boundaries and satisfy auditor requirements, which approach correctly maps the shared responsibility model across these service tiers and identifies the appropriate compliance artifact retrieval process?
In the Google Cloud shared responsibility model, compliance and operational obligations vary significantly across Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) models. To validate compliance for cloud-hosted environments, customers must manage their scoped responsibilities while leveraging Google Cloud Compliance Reports Manager (or designated compliance resources) to download independent third-party attestations like SOC 2 reports and PCI Attestation of Compliance (AOC) documents.
This solution correctly delineates control ownership at each specific cloud service abstraction level and establishes a defensible audit trail using official third-party compliance attestations.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.