Be able to select the right control for a stated compliance requirement: Assured Workloads for regime-based folders, location, and personnel controls; Bucket Lock for immutable retention; Access Transparency and Access Approval for Google personnel access. The key is matching the requirement to the enforcing mechanism, not just a monitoring feature.
Start practicing
Supporting Compliance Requirements — choose a session length
Free · No account required
Domain overview
This domain covers how Google Cloud services map to regulatory and contractual obligations: Assured Workloads regimes, resource location restrictions, personnel access controls, retention and immutability, and audit evidence. Questions present a compliance scenario and ask which controls, services, or settings satisfy it, so you must connect a requirement to the specific Google Cloud mechanism that enforces it.
Exam objectives
Assured Workloads regimes (ITAR, FEDRAMP_HIGH, IL4) and their preconfigured organization policies
Resource location restrictions via organization policy constraints and Assured Workloads folder boundaries
Personnel access controls including Access Transparency and Access Approval
Immutable retention using Cloud Storage Bucket Lock and retention policies
Treating Assured Workloads as a monitoring-only tool, ignoring that it provisions folders, policies, and access controls
Assuming standard IAM alone prevents administrators from deleting data, when Bucket Lock is required for immutability
Confusing Access Transparency (logs Google access) with Access Approval (requires customer approval for that access)
Click any question to see the full explanation and answer options, or start a focused practice session above.
A healthcare organization is required to protect Protected Health Information (PHI) stored in Cloud Storage. They want to automatically detect and redact PHI before storing it. Which Google Cloud service should they use?
2A company needs to retain audit logs for 7 years to meet compliance requirements. By default, Cloud Audit Logs are retained for 30 days. What should they do to retain the logs for 7 years?
3A financial institution is deploying a payment application on GKE that must comply with PCI DSS. They need to isolate the cardholder data environment (CDE) from other workloads and ensure only authorized services can communicate. Which combination of controls should they implement?
4An organization handles ITAR-controlled data and must restrict Google personnel access to the underlying infrastructure. Which Google Cloud product should they use to enforce this restriction?
5A company processes personal data of European Union residents on GCP. They need to ensure that data processing is limited to specific purposes and that data subjects can exercise their rights (access, rectification, erasure). Which actions should they take to comply with GDPR?
6A security engineer wants to test a web application hosted on Compute Engine for vulnerabilities. According to Google Cloud's Acceptable Use Policy, which of the following is true regarding penetration testing?
7Which Google Cloud compliance certification requires the customer to sign a Business Associate Agreement (BAA) with Google?
8A government contractor needs to deploy workloads on GCP that meet FedRAMP High baseline requirements. They want to enforce resource location restrictions and access controls for Google personnel. Which product should they use?
9A company is migrating a PCI DSS-compliant application to GCP. They need to meet encryption requirements for cardholder data. Which TWO options satisfy PCI DSS encryption requirements? (Choose two.)
10A company processes healthcare data and has signed a BAA with Google Cloud. They need to implement controls for HIPAA compliance. Which THREE actions should they take? (Choose three.)
11A healthcare organization is migrating to Google Cloud and needs to store Protected Health Information (PHI) while maintaining HIPAA compliance. They have executed a Business Associate Agreement (BAA) with Google. Which additional step is required to ensure that PHI is properly classified and protected?
12A company needs to ensure that all data stored in Cloud Storage is encrypted at rest using keys that they generate and manage themselves. They also need to rotate the keys every 90 days. Which encryption option should they use?
13A security engineer needs to audit changes to IAM policies across their Google Cloud organization. Which audit log type should they enable to capture IAM policy changes?
14Which Google Cloud service is specifically designed to help customers meet compliance requirements by creating a folder with pre-defined organization policies, resource location restrictions, and access controls?
15A security team wants to monitor for compliance drift in an Assured Workloads folder that enforces FedRAMP High controls. Which Google Cloud service should they use to detect violations of organization policies?
16A company is required to perform penetration testing on their Google Cloud infrastructure. According to Google Cloud's policy, which statement is true regarding penetration testing?
17A company is designing a PCI DSS-compliant environment on Google Cloud. They need to isolate the cardholder data environment (CDE) and log all access to it. Which THREE actions should they take? (Choose 3)
18A multinational company must comply with GDPR and needs to ensure that personal data is processed in a manner that respects data subject rights. Which TWO of the following are required under GDPR? (Choose 2)
19A healthcare organization is migrating to Google Cloud and needs to store Protected Health Information (PHI) in Cloud Storage. They have signed a Business Associate Agreement (BAA) with Google. Which additional step is REQUIRED to ensure HIPAA compliance for the data stored?
20A financial institution is deploying a PCI DSS-compliant web application on Google Cloud. They need to isolate the cardholder data environment (CDE) from other environments and protect the web application against common web attacks. Which combination of services meets these requirements?
21A company is using Assured Workloads to enforce FEDRAMP_HIGH compliance. They need to ensure that only US-based personnel from Google can access their data. Which configuration setting within the Assured Workloads folder should they enable?
22Which Google Cloud service can automatically classify and de-identify sensitive data such as credit card numbers and health records before it is stored in Cloud Storage?
23A company needs to store financial records for 7 years to meet regulatory requirements. They want to ensure that once written, the records cannot be modified or deleted by anyone, including cloud administrators. Which Cloud Storage feature should they enable?
24A security engineer needs to run a penetration test against their Google Cloud environment. According to Google's Acceptable Use Policy, which of the following is true regarding penetration testing?
25A healthcare organization needs to ensure that all access to ePHI in Cloud SQL is logged for HIPAA compliance. They have enabled audit logs. What additional step is required to ensure logs are retained for at least one year?
26An organization is using Assured Workloads to enforce ITAR compliance. They need to ensure that all resources are deployed in specific US regions and that Google personnel access is restricted. They also want to monitor for any configuration changes that violate compliance policies. Which service should they use for monitoring compliance drift?
27Which Google Cloud compliance certification is most relevant for a company that processes credit card transactions and needs to demonstrate secure handling of cardholder data?
28A company wants to encrypt data at rest in Cloud Storage using their own keys. Which Cloud service should they use to manage these keys?
29A company is using Assured Workloads with the FEDRAMP_HIGH regime. They need to restrict where resources can be created and monitor for compliance violations. Which TWO settings should they configure? (Choose 2)
30A healthcare organization is migrating workloads to Google Cloud and needs to process Protected Health Information (PHI) under HIPAA. Which step is required before storing PHI in any GCP service?
31A financial institution is required to retain records of all transactions for 7 years under regulatory compliance. They are using Cloud Storage for archive data and need to ensure that objects cannot be deleted or overwritten during the retention period. Which feature should they use?
32A company using Google Cloud wants to conduct a penetration test on their infrastructure. According to Google's acceptable use policy, what must they do before testing?
33A company handles Controlled Unclassified Information (CUI) and needs to deploy a workload that complies with ITAR (International Traffic in Arms Regulations). They plan to use Assured Workloads. Which compliance regime should they select when creating the Assured Workloads folder?
34A company has deployed an application in Assured Workloads with the FEDRAMP_HIGH compliance regime. They need to ensure that Google Cloud personnel cannot access their data. Which additional control should they enable?
35A company wants to ensure that data stored in Cloud Storage is encrypted at rest using keys that they generate and manage on-premises. Which encryption method should they use?
36A company is subject to PCI DSS and needs to protect a web application that processes credit card data. They want to block common web attacks such as SQL injection and cross-site scripting (XSS). Which Google Cloud service should they use?
37A company is deploying a workload that must comply with FedRAMP High. They are using Assured Workloads. Which TWO controls are automatically enabled when they select the FEDRAMP_HIGH regime?
38A healthcare organization is migrating PHI workloads to Google Cloud and needs to encrypt data at rest with keys that are generated and managed within their own on-premises hardware security module (HSM). Which encryption approach should they use?
39A company needs to retain critical financial records for 7 years to comply with SEC regulations. They choose to store the records in Cloud Storage. Which feature should they enable to ensure the records cannot be deleted or overwritten before the retention period expires?
40A financial institution is deploying a PCI DSS-compliant cardholder data environment (CDE) on Google Cloud. They need to segment the CDE from other environments and restrict data egress from the CDE. Which two services should they use together? (Choose the best combination.)
41An organization wants to run a penetration test on their Google Cloud environment to validate security controls. According to Google's Acceptable Use Policy, which of the following is true regarding penetration testing?
42A company that stores protected health information (PHI) in Google Cloud wants to run a BigQuery query to identify and classify sensitive data such as patient names and social security numbers. Which Google Cloud service should they use?
43A company is implementing a HIPAA-compliant environment on Google Cloud. They need to ensure that all access to protected health information (PHI) is logged and monitored. Which TWO steps should they take? (Choose two.)
44A company subject to PCI DSS is building a cardholder data environment (CDE) on Google Cloud. They need to encrypt cardholder data at rest and in transit. Which THREE measures should they implement? (Choose three.)
45A company uses Assured Workloads with the FEDRAMP_HIGH regime. They want to enforce resource location restrictions and restrict Google personnel access. Which TWO capabilities should they enable? (Choose two.)
46A company is designing a PCI DSS-compliant architecture on Google Cloud. They need to ensure that the cardholder data environment (CDE) is isolated from other environments and that all access to the CDE is logged. Which THREE controls should they implement? (Choose three.)
47A company is subject to SOC 2 compliance and wants to demonstrate that they have implemented proper access controls on Google Cloud. Which TWO IAM best practices should they follow? (Choose two.)
48A healthcare company must demonstrate to auditors that access to patient data in Google Cloud is granted only to authorized personnel and that all access is logged. They want to prove that permissions are reviewed quarterly and that no excessive access exists. Which Google Cloud capability should they use to generate evidence of who has access to which resources and how that access is used?
49A healthcare analytics company must demonstrate to auditors that access to its Cloud Storage buckets containing protected health information (PHI) is limited to authorized personnel and that access is reviewed regularly. They want to automate the collection of evidence showing which IAM principals have access to these buckets and when that access was last used. Which Google Cloud service should they use to generate this compliance evidence?
50A multinational corporation must comply with data residency requirements for several countries. They are using Google Cloud and need to ensure that data for European users stays within the EU, while data for US users stays in the US. They also need to prove compliance to regulators. Which Google Cloud feature should they implement to enforce and monitor data residency at the resource level?
51A multinational bank must ensure that its Google Cloud resources for a new trading platform are deployed only in regions within the European Union and that support access is restricted to EU-based Google personnel. They also need to monitor for any configuration drift that could violate these requirements. Which Google Cloud feature should they implement to meet these compliance obligations?
52A healthcare analytics company runs workloads on Google Cloud and must demonstrate HIPAA compliance to auditors. The security team needs a Google-provided artifact that documents how Google's infrastructure controls map to HIPAA requirements so they can incorporate it into their own compliance documentation. Which resource should they use?
53A company is preparing for a SOC 2 audit and needs to demonstrate that changes to production Google Cloud resources are tracked and approved. They want to ensure that all modifications to IAM policies, firewall rules, and Cloud Storage buckets are logged and that the logs cannot be altered. Which Google Cloud service should they use to collect and retain these logs immutably?
54A multinational bank must prove that its Google Cloud resources for a regulated trading platform remain in Canadian regions only, and it needs continuous monitoring that alerts when any resource is deployed outside the allowed locations. The team wants a managed Google Cloud capability rather than custom scripts. What should they implement?
55A financial services company must comply with the Payment Card Industry Data Security Standard (PCI DSS) on Google Cloud. They need to ensure that cardholder data is protected both at rest and in transit. Which two Google Cloud configurations should they implement to meet these requirements? (Choose two.)
56A software company plans to store EU customer personal data in Cloud Storage and BigQuery under a Data Processing Addendum with Google. The legal team asks the security engineer which Google Cloud commitment guarantees that customer data will not be accessed for advertising purposes and will be handled only per the customer's instructions. What should the engineer cite?
57A retail enterprise is preparing for a SOC 2 Type II audit of its Google Cloud environment. The security team must collect evidence that shows who changed firewall rules and IAM policies, and that shows whether privileged access was reviewed over the audit period. Which two Google Cloud capabilities should they use to gather this evidence? (Choose two.)
58A healthcare company stores electronic protected health information (ePHI) in Cloud Storage and BigQuery. During a compliance audit, they must demonstrate that access to ePHI is logged and that any modification to ePHI can be traced. Which Google Cloud feature should they enable to meet this requirement?
59Your organization runs a regulated workload on Google Cloud and must demonstrate compliance with ISO/IEC 27001 to an external auditor. The auditor requires an on-demand, point-in-time report showing which controls were in place and how Google Cloud infrastructure was configured during a specific audit period. Which Google Cloud resource should you use to provide this evidence?
60A healthcare company processes protected health information (PHI) on Google Cloud and must comply with HIPAA. They need to ensure that all data at rest in Cloud Storage, BigQuery, and Cloud SQL is encrypted with keys they control, and that key usage is logged for audit. Which combination of Google Cloud services should they implement to meet these requirements?
61A multinational corporation must ensure that its Google Cloud resources for a new application are deployed only in the European Union to comply with GDPR data residency requirements. The security team wants to enforce this automatically and receive alerts if any resource is created outside the allowed regions. Which Google Cloud service should they use?
62Your company must comply with the Payment Card Industry Data Security Standard (PCI DSS) for a new e-commerce application on Google Cloud. The security team needs to understand which aspects of PCI DSS compliance are Google's responsibility and which are theirs. According to the Google Cloud shared responsibility model, which of the following is a customer responsibility?
63A healthcare analytics company stores patient records in Cloud Storage and BigQuery. A compliance officer requires an automated, recurring scan of these data sources to discover sensitive data such as personally identifiable information (PII) and protected health information (PHI), and to produce findings that can be reviewed for audit. The security team wants minimal operational overhead and no custom code. Which Google Cloud service should they use to meet this requirement?
64A multinational corporation must comply with the EU General Data Protection Regulation (GDPR) and ensure that personal data of EU residents is not transferred outside the EU. They are using BigQuery for analytics and want to enforce that all datasets containing personal data are created only in EU regions. Which Google Cloud feature should they use to meet this requirement?
65A multinational retailer must demonstrate to an auditor that its Google Cloud environment enforces data residency for a regulated workload in a specific jurisdiction. The security team wants Google Cloud to deploy and monitor the workload against a predefined control package aligned to that jurisdiction, including automatic monitoring for compliance violations. Which Google Cloud solution should they use?
66A financial services firm is preparing for a compliance audit of its Google Cloud environment. The auditor asks for evidence that access to sensitive production projects is governed and that administrative actions are traceable. The security team needs to produce configuration and activity evidence from Google Cloud. (Choose two.)
67A startup must satisfy a compliance requirement to prove that its production data stored in Cloud Storage has not been altered or deleted by an insider or a compromised account. The security team wants a control that prevents any user, including project owners, from deleting or modifying objects for a defined period, and that provides an audit trail of the retention. Which Cloud Storage feature should they enable?
68A healthcare company must prove to regulators that protected health information stored in Cloud Storage is encrypted with keys it controls and that key usage is independently auditable. The security team wants to rotate keys on a defined schedule without re-encrypting existing objects and must be able to revoke access instantly if a key is compromised. Which configuration should they implement?
69A company operates in a region with strict data protection law. The security team must ensure that log data containing end-user identifiers is stored only in that region and cannot be replicated or accessed from other regions, while still allowing central security analysts to query it. Which approach best meets the residency requirement?
70A company is deploying a workload that handles Controlled Unclassified Information (CUI) and must comply with DFARS 252.204-7012. They need to ensure that all data remains within the United States and that only U.S. persons can access it. They also need to generate compliance reports for auditors. Which Google Cloud service should they use?
71A company is preparing for a SOC 2 Type II audit. They need to demonstrate that access to their Google Cloud environment is controlled and monitored. Which two Google Cloud features should they implement to meet the access control and monitoring requirements? (Choose two.)
72A multinational bank operates in several countries and must keep certain customer data within specific jurisdictions while still allowing a global security team to monitor for threats. The security team needs to detect anomalous access attempts across all regions without moving or replicating the regulated data outside its approved location. Which approach best satisfies both the data residency requirement and the global monitoring need?
Be able to select the right control for a stated compliance requirement: Assured Workloads for regime-based folders, location, and personnel controls; Bucket Lock for immutable retention; Access Transparency and Access Approval for Google personnel access. The key is matching the requirement to the enforcing mechanism, not just a monitoring feature.
The Courseiva PCSE question bank contains 72 questions in the Supporting Compliance Requirements domain, covering the 11% of the exam attributed to this domain in the official Google Cloud blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Supporting Compliance Requirements domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included