Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A financial enterprise is preparing for an annual multi-framework compliance audit (including ISO/IEC 27001, SOC 2 Type II, and PCI DSS) for a cloud-native transaction processing application hosted on Google Cloud.
The external compliance auditor mandates two distinct verification streams:
Which strategy correctly satisfies these requirements under the Google Cloud shared responsibility model?
Retrieve Google's third-party SOC reports, ISO certifications, and PCI Attestation of Compliance (AOC) for underlying infrastructure assurance; enable Cloud Audit Logs and Access Transparency for administrative oversight; and perform customer application penetration testing without requiring prior approval from Google.
Rely entirely on Google's Cloud Data Processing Addendum and Data Controller status to satisfy customer application audit criteria, while using the Google Cloud Status Dashboard as the sole mechanism for logging internal and administrative system access.
Schedule a direct on-site physical inspection of Google data center facilities for the external auditor, disable Access Transparency to prevent vendor credential logging, and submit formal written requests to Google Support prior to conducting any penetration tests.
Inherit Google's public SOC 3 report to satisfy all customer-side operating system and application controls, rely on Binary Authorization for Borg deployment integrity logs, and submit requests to Google's security engineering team to conduct custom vulnerability scans.
Retrieve Google's third-party SOC reports, ISO certifications, and PCI Attestation of Compliance (AOC) for underlying infrastructure assurance; enable Cloud Audit Logs and Access Transparency for administrative oversight; and perform customer application penetration testing without requiring prior approval from Google.
Under the Google Cloud shared responsibility model, compliance assurance is divided between the cloud service provider (security of the cloud) and the customer (security in the cloud). Customers validate Google's underlying physical infrastructure, datacenter operations, hardware root of trust, and hypervisor controls by reviewing independent third-party audit attestations—including SOC 1/2/3 reports, ISO/IEC 27001/27017/27018 certifications, and PCI Attestation of Compliance (AOC) available through the Compliance Reports Manager or Google Cloud representative.
This approach cleanly fulfills regulatory boundaries by relying on verified external attestations for vendor-managed layers while actively architecting detective, preventive, and assessment controls across customer-managed assets.
Rely entirely on Google's Cloud Data Processing Addendum and Data Controller status to satisfy customer application audit criteria, while using the Google Cloud Status Dashboard as the sole mechanism for logging internal and administrative system access.
Schedule a direct on-site physical inspection of Google data center facilities for the external auditor, disable Access Transparency to prevent vendor credential logging, and submit formal written requests to Google Support prior to conducting any penetration tests.
Inherit Google's public SOC 3 report to satisfy all customer-side operating system and application controls, rely on Binary Authorization for Borg deployment integrity logs, and submit requests to Google's security engineering team to conduct custom vulnerability scans.