Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A multinational financial services institution is migrating a mission-critical payment processing system to Google Cloud. The compliance and security teams mandate a comprehensive, end-to-end data protection strategy that enforces strict data confidentiality across all stages of the data lifecycle:
Which architecture meets all of these end-to-end data protection requirements?
Deploy standard Google Kubernetes Engine (GKE) clusters using Sensitive Data Protection to de-identify data fields before writing to storage, and enforce Binary Authorization on container deployments.
Deploy standard Compute Engine instances inside a VPC Service Controls perimeter, enforce Private Google Access for service communications, and implement Cloud Armor security policies on ingress endpoints.
Deploy the processing workloads on Confidential VM instances utilizing hardware-based memory encryption, enforce TLS 1.2+ using Cloud Load Balancing SSL policies for in-transit traffic, and encrypt all persistent disks and storage using Customer-Managed Encryption Keys (CMEK) backed by Cloud HSM.
Deploy the processing workloads on Shielded VM instances with Secure Boot and vTPM enabled, enforce IPSec tunnels across internal VPCs, and rely on default Google-managed encryption keys for storage and persistent disk protection.
Deploy standard Google Kubernetes Engine (GKE) clusters using Sensitive Data Protection to de-identify data fields before writing to storage, and enforce Binary Authorization on container deployments.
Deploy standard Compute Engine instances inside a VPC Service Controls perimeter, enforce Private Google Access for service communications, and implement Cloud Armor security policies on ingress endpoints.
Deploy the processing workloads on Confidential VM instances utilizing hardware-based memory encryption, enforce TLS 1.2+ using Cloud Load Balancing SSL policies for in-transit traffic, and encrypt all persistent disks and storage using Customer-Managed Encryption Keys (CMEK) backed by Cloud HSM.
This architecture combines Confidential Computing, Customer-Managed Encryption Keys (CMEK) with Cloud HSM, and managed SSL/TLS Policies on Cloud Load Balancing to achieve comprehensive cryptographic protection across data at rest, data in transit, and data in use.
This solution directly addresses every stage of the data lifecycle without operational blind spots, ensuring data confidentiality is maintained from network transit to persistent storage and active memory execution.
Deploy the processing workloads on Shielded VM instances with Secure Boot and vTPM enabled, enforce IPSec tunnels across internal VPCs, and rely on default Google-managed encryption keys for storage and persistent disk protection.