Soru

Zorluk: KolayRegulatory Compliance, Data Sovereignty, and Data Governance

An organization must enforce strict data sovereignty and data governance controls for sensitive data stored in Google Cloud. The compliance mandate requires restricting all data storage resources to a specific geographic region and managing encryption keys centrally using Google Cloud services. Which TWO architectural actions should the organization take to satisfy these requirements? (Select TWO)

  1. Enforce the Resource Locations organization policy constraint (constraints/gcp.resourceLocations) to restrict resource deployment exclusively to the designated region.Cevap
  2. Encrypt cloud storage and database resources using Customer-Managed Encryption Keys (CMEK) hosted in Cloud KMS within the designated region.Cevap
  3. C
    Require Customer-Supplied Encryption Keys (CSEK) by transmitting raw key material in headers with every storage API request to meet central key management standards.
  4. D
    Grant primitive Owner roles to security auditors across all projects to ensure full oversight and administrative access to compliance settings.

Cevap

Enforce the Resource Locations organization policy constraint to restrict resource deployment to the designated region, and encrypt storage resources using Customer-Managed Encryption Keys (CMEK) hosted in Cloud KMS.
To comply with data sovereignty and governance mandates, organizations should enforce the Resource Locations organization policy constraint to restrict resource creation to specific geographical boundaries, and use Customer-Managed Encryption Keys (CMEK) stored in regional Cloud KMS to maintain centralized control and auditability over key lifecycles.

Adım Adım Çözüm

1
Identify the data sovereignty requirement for geographic restriction
Apply the Organization Policy constraint for Resource Locations to restrict resource creation strictly to the allowed GCP region.
Organization policies provide programmatic compliance guardrails across the resource hierarchy.
2
Identify the central key management requirement
Configure Customer-Managed Encryption Keys (CMEK) via Cloud KMS within the compliant region.
CMEK allows central control, auditing, and key rotation management without requiring clients to supply raw keys on every request.

Anahtar Kavram

Data sovereignty controls using Organization Policies and centralized key governance with Customer-Managed Encryption Keys (CMEK).
Bu soruyu puanla