GCP PCA · Question 11 · Domain 3: Designing for Security and Compliance
CASE STUDY: CareData Health
Company Overview:
CareData Health is a large healthcare provider network operating 50 hospitals. They manage petabytes of patient records, medical imaging, and telemetry data.
Current Technical Environment:
Business Requirements:
Executive Statements:
Technical Requirements:
Constraints:
QUESTION:
To meet the CISO's requirement of preventing unauthorized data exfiltration from the centralized data lake (BigQuery and Cloud Storage), which security control should you implement?
Answer options:
Implement Cloud Armor policies to block all external IP addresses.
Configure VPC Service Controls to create a secure perimeter around the GCP projects containing the data lake.
Use Identity-Aware Proxy (IAP) to require multi-factor authentication for all database queries.
Remove all external IP addresses from the Compute Engine instances.
50 questions · hints · full answers · grading