Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An organization is migrating its financial transaction processing workloads to Google Cloud and preparing for an upcoming PCI DSS and SOC 2 Type II compliance audit. The target environment includes:
To establish the compliance boundaries and satisfy auditor requirements, which approach correctly maps the shared responsibility model across these service tiers and identifies the appropriate compliance artifact retrieval process?
Enforce customer-managed operating system patch cycles on Cloud SQL instances, configure VPC Service Controls across Google Workspace user identities, and rely on Cloud Logging without obtaining third-party compliance reports.
Delegate the physical data center audits and hypervisor vulnerability remediation to the internal security team, and execute manual on-site inspections of Google Cloud facilities to satisfy PCI DSS physical security requirements.
Rely on Google's PCI DSS certification to inherit full compliance across Compute Engine guest operating systems and Cloud SQL database engines, and submit a customer penetration test exemption request through the Google Cloud console.
Manage guest OS patching, network firewalls, and application configurations on Compute Engine; configure database access controls and schema encryption on Cloud SQL; enforce identity and user access policies in Google Workspace; and obtain Google's PCI Attestation of Compliance (AOC) and SOC 2 Type II reports from the Compliance Reports Manager.
Enforce customer-managed operating system patch cycles on Cloud SQL instances, configure VPC Service Controls across Google Workspace user identities, and rely on Cloud Logging without obtaining third-party compliance reports.
Delegate the physical data center audits and hypervisor vulnerability remediation to the internal security team, and execute manual on-site inspections of Google Cloud facilities to satisfy PCI DSS physical security requirements.
Rely on Google's PCI DSS certification to inherit full compliance across Compute Engine guest operating systems and Cloud SQL database engines, and submit a customer penetration test exemption request through the Google Cloud console.
Manage guest OS patching, network firewalls, and application configurations on Compute Engine; configure database access controls and schema encryption on Cloud SQL; enforce identity and user access policies in Google Workspace; and obtain Google's PCI Attestation of Compliance (AOC) and SOC 2 Type II reports from the Compliance Reports Manager.
In the Google Cloud shared responsibility model, compliance and operational obligations vary significantly across Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) models. To validate compliance for cloud-hosted environments, customers must manage their scoped responsibilities while leveraging Google Cloud Compliance Reports Manager (or designated compliance resources) to download independent third-party attestations like SOC 2 reports and PCI Attestation of Compliance (AOC) documents.
This solution correctly delineates control ownership at each specific cloud service abstraction level and establishes a defensible audit trail using official third-party compliance attestations.