Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An organization is preparing for a PCI-DSS compliance audit of its cloud workloads. The security team discovers that cardholder data, including Primary Account Numbers (PAN), is mixed with non-regulated operational data across multiple BigQuery datasets and Compute Engine workloads.
To reduce the compliance audit footprint and establish a secure Cardholder Data Environment (CDE), the organization must:
Which strategy should the security engineer implement to achieve these objectives?
Configure Organization Policy constraints to restrict resource deployment to US regions, configure Cloud NAT on all VPC subnets, and set immutable retention periods using Cloud Storage Bucket Lock on all data exports.
Maintain all data in the existing shared projects, apply dataset-level IAM viewer permissions, establish VPC Network Peering between subnets, and configure Cloud Armor edge security policies on incoming traffic.
Deploy Web Security Scanner across Compute Engine workloads, connect all project VPCs using Cloud VPN with IPsec encryption, and enforce multi-factor authentication via Cloud Identity.
Use Sensitive Data Protection (Cloud DLP) to discover and classify PAN data, tag assets in Data Catalog, migrate regulated workloads into dedicated projects inside a segregated folder, and enclose them within a VPC Service Controls service perimeter while applying BigQuery policy tags for column-level access.
Configure Organization Policy constraints to restrict resource deployment to US regions, configure Cloud NAT on all VPC subnets, and set immutable retention periods using Cloud Storage Bucket Lock on all data exports.
Maintain all data in the existing shared projects, apply dataset-level IAM viewer permissions, establish VPC Network Peering between subnets, and configure Cloud Armor edge security policies on incoming traffic.
Deploy Web Security Scanner across Compute Engine workloads, connect all project VPCs using Cloud VPN with IPsec encryption, and enforce multi-factor authentication via Cloud Identity.
Use Sensitive Data Protection (Cloud DLP) to discover and classify PAN data, tag assets in Data Catalog, migrate regulated workloads into dedicated projects inside a segregated folder, and enclose them within a VPC Service Controls service perimeter while applying BigQuery policy tags for column-level access.
This architecture combines automated sensitive data discovery, organizational segregation, network perimeter enforcement, and fine-grained data governance to cleanly isolate and minimize the Cardholder Data Environment (CDE) scope under PCI-DSS.
CREDIT_CARD_NUMBER / PAN infoTypes. Integrating this with Data Catalog automatically applies business metadata tags and sensitivity classifications to datasets, tables, and columns.This solution directly satisfies the principle of least scope by separating regulated assets into dedicated container projects, applying strict perimeter isolation using VPC Service Controls, and cataloging all cardholder data automatically.