Soru

Zorluk: OrtaRegulatory Compliance, Data Sovereignty, and Data Governance

A French biotechnology enterprise is migrating its genomic clinical trial pipeline to Google Cloud. To satisfy strict EU data sovereignty mandates and data governance requirements, the solution must meet three specific criteria:
1. Cryptographic keys used for data at rest must be managed within Cloud KMS hosted in a specified EU region.
2. Google Cloud personnel must obtain explicit customer authorization before accessing data during support operations.
3. Authenticated identities must be prevented from exfiltrating sensitive genomic datasets to external, unauthorized Google Cloud storage resources.

Which combination of Google Cloud security controls satisfies these compliance and governance requirements?

  1. Configure Customer-Managed Encryption Keys (CMEK) with key rings hosted in the target EU region, enable Access Approval for operator access, and establish a VPC Service Controls perimeter around project resources.Cevap
  2. B
    Mandate Customer-Supplied Encryption Keys (CSEK) for key management governance, enable Access Transparency logs, and grant primitive Owner roles to administrators to enforce security access controls.
  3. C
    Configure Customer-Managed Encryption Keys (CMEK) hosted in an EU key ring, enable Access Approval, and rely exclusively on fine-grained Identity and Access Management (IAM) permissions to block data exfiltration.
  4. D
    Grant the Service Account Admin role to application compute workloads, configure CMEK with EU key rings, and enable Cloud Audit Logs without configuring Access Approval.

Cevap

Configure Customer-Managed Encryption Keys (CMEK) with key rings hosted in the target EU region, enable Access Approval for operator access, and establish a VPC Service Controls perimeter around project resources.
The correct choice fulfills all three regulatory requirements. Customer-Managed Encryption Keys (CMEK) constrained to an EU Cloud KMS key ring satisfies data sovereignty encryption rules. Access Approval ensures Google Cloud personnel require explicit customer consent before accessing resources. VPC Service Controls provides perimeter security to prevent data exfiltration by authorized identities.

Adım Adım Çözüm

1
Address key management and regional sovereignty requirements.
Using Customer-Managed Encryption Keys (CMEK) with key rings located in the specified EU region ensures compliance with regional data encryption governance without taking on raw CSEK key management burdens.
CMEK allows key lifecycle control while keeping key rings strictly constrained to approved geographic regions.
2
Address operator access governance requirements.
Enabling Access Approval ensures Google support engineers cannot access data or configuration without prior customer consent.
Access Approval enforces administrative approval workflows for Google Cloud support interactions.
3
Address data exfiltration prevention requirements.
Deploying VPC Service Controls isolates storage and compute resources within a perimeter, preventing authorized users from copying data to external resources.
IAM permissions govern access, but VPC Service Controls enforces network-level boundary protection against exfiltration.

Anahtar Kavram

Combining CMEK, Access Approval, and VPC Service Controls for regulatory compliance and data sovereignty
Bu soruyu puanla