Courseiva
Why Cloud Technology Can Transform BusinesshardMultiple SelectObjective-mapped

Cloud Digital Leader Why Cloud Technology Can Transform Business Practice Question

A financial company wants to run sensitive workloads on Google Cloud while ensuring data never leaves a specific geographic boundary and meets strict compliance requirements. Which THREE Google Cloud services should they combine?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Assured Workloads for Government

VPC Service Controls create security perimeters to prevent data exfiltration. Assured Workloads provides compliance controls for regulated industries (e.g., FedRAMP). Cloud HSM with CMEK ensures customer-managed keys in hardware for encryption compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Cloud VPN

    Why it's wrong here

    Cloud VPN establishes encrypted IPsec tunnels between a customer's on-premises network and a Google Cloud VPC, enabling hybrid connectivity. However, it functions purely at the network layer and does not enforce any geographic restrictions on data storage or processing, nor does it provide compliance controls. While it secures data in transit, it cannot constrain where sensitive workloads reside or how their data is accessed, making it unsuitable for meeting regulatory residency requirements.

  • Assured Workloads for Government

    Why this is correct

    Assured Workloads for Government is a comprehensive compliance service that creates a dedicated folder within your Google Cloud organization, enforcing specific data residency, access control, and encryption requirements mandated by FedRAMP High or IL4. It integrates with Access Transparency and CMEK, and automatically applies key access controls to prevent unauthorized access by Google personnel. This provides a certified boundary around sensitive workloads, making it the correct choice for regulated data.

  • Cloud NAT

    Why it's wrong here

    Cloud NAT allows private instances without external IP addresses to make outbound connections to the internet, while still receiving inbound responses, but it does not permit inbound connections. It is a translation service that provides IP source NAT, not a data governance or compliance mechanism. Cloud NAT has no awareness of data sensitivity, geographic jurisdiction, or regulatory requirements, and it cannot enforce data residency or prevent exfiltration.

  • Cloud HSM with CMEK

    Why this is correct

    Cloud HSM with CMEK provides customer-managed encryption keys that are generated and used in a FIPS 140-2 Level 3 certified hardware security module, giving you control over key lifecycle including rotation and deletion. While it is an important security control for protecting data at rest, it addresses only the encryption aspect of compliance. Cloud HSM with CMEK does not enforce data residency or restrict Google's access to the associated data, so it is insufficient on its own for a regulated workload.

  • VPC Service Controls

    Why this is correct

    VPC Service Controls create security perimeters around Google Cloud resources, such as GCS buckets and BigQuery datasets, preventing data from being exfiltrated to unauthorized networks or clients. By using context-based rules, you can restrict resource access based on identity and location, but this is a network-level and IAM-level mitigation. It does not automatically ensure compliance with specific regulatory standards like FedRAMP High, nor does it manage encryption keys or provide the full operational governance that Assured Workloads delivers.

About these practice questions

This GCDL question is part of Courseiva's 829-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.