Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise is deploying an AI agent solution built on the Gemini platform on Google Cloud. The architecture processes real-time user prompts, retrieves context from backend storage, and persists conversation history and model outputs.
The security team mandates the following compliance and data governance requirements:
europe-west1 region and be prevented from crossing virtual network boundaries.Which combination of security controls should the security engineer implement?
Implement Private Services Access with VPC Network Peering to access AI APIs; apply Cloud Storage Bucket Lock policies to prevent modification; and generate asymmetric signing keys in Cloud KMS to de-identify prompt payloads.
Call the global Cloud DLP endpoint with the location parameter set to locations/europe-west1/content:deidentify; apply the constraints/gcp.resourceLocations organization policy; configure default Google-managed encryption keys; and rely on Cloud Armor WAF rules to restrict API egress across regions.
Configure asynchronous Cloud DLP scheduled inspection job triggers on backend Cloud Storage buckets; enable Cloud KMS Autokey in multi-region europe; and use Serverless VPC Access connectors without VPC Service Controls perimeters.
Configure real-time prompt and output sanitization using the Cloud DLP synchronous content.deidentify method targeting the dlp.europe-west1.rep.googleapis.com regional endpoint; enforce the constraints/gcp.restrictEndpointUsage and constraints/gcp.resourceLocations organization policies; enclose services within a VPC Service Controls perimeter; and configure CMEK using Cloud KMS keys created in europe-west1.
Implement Private Services Access with VPC Network Peering to access AI APIs; apply Cloud Storage Bucket Lock policies to prevent modification; and generate asymmetric signing keys in Cloud KMS to de-identify prompt payloads.
Call the global Cloud DLP endpoint with the location parameter set to locations/europe-west1/content:deidentify; apply the constraints/gcp.resourceLocations organization policy; configure default Google-managed encryption keys; and rely on Cloud Armor WAF rules to restrict API egress across regions.
Configure asynchronous Cloud DLP scheduled inspection job triggers on backend Cloud Storage buckets; enable Cloud KMS Autokey in multi-region europe; and use Serverless VPC Access connectors without VPC Service Controls perimeters.
Configure real-time prompt and output sanitization using the Cloud DLP synchronous content.deidentify method targeting the dlp.europe-west1.rep.googleapis.com regional endpoint; enforce the constraints/gcp.restrictEndpointUsage and constraints/gcp.resourceLocations organization policies; enclose services within a VPC Service Controls perimeter; and configure CMEK using Cloud KMS keys created in europe-west1.
This architecture combines Sensitive Data Protection (Cloud DLP) regional endpoints, VPC Service Controls, Cloud KMS, and Organization Policy Service constraints to establish end-to-end data governance, strict data residency, and encryption for AI workloads.
content.deidentify API method of Cloud DLP inspects and de-identifies prompt strings and model responses in real time before data reaches persistent backend storage.dlp.europe-west1.rep.googleapis.com ensures that TLS sessions terminate inside europe-west1, guaranteeing that data at rest, in use, and in transit never leaves the specified region. Enforcing constraints/gcp.restrictEndpointUsage prevents client calls from accidentally routing to global endpoints.constraints/gcp.resourceLocations limits resource provisioning strictly to europe-west1 across all projects.europe-west1 wrap local data encryption keys (DEKs) ensuring full customer control over encryption at rest.content methods sanitizes generative AI inputs and outputs before storage.