Cloud Digital Leader Why Cloud Technology Can Transform Business Practice Question
A financial services company must comply with regulations requiring data residency within the EU. They want to run workloads on Google Cloud. Which action should they take?
⚠ Common exam trap
GCDL often tests the misconception that encryption at rest or private networking equals data residency — candidates pick 'enable encryption' when the question is really about physical location of storage and processing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Select a Google Cloud region located in the EU
Data residency requirements are satisfied by physically storing and processing data within a specific geographic boundary, which in Google Cloud means selecting a region (or regions) located inside the EU, such as europe-west1, europe-west3, or europe-north1. Choosing an EU region ensures that at-rest storage, compute, and default replication stay within EU soil, meeting GDPR-style residency mandates. Encryption and network connectivity do not change where data physically resides.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a multi-region deployment with regions in the US and EU
Why it's wrong here
A multi-region deployment with regions in the US and EU replicates data and workloads across at least two geopolitical locations, meaning copies of regulated financial data would reside on US soil. Even if you prefer the EU multi-region location, explicitly including a US region breaks the requirement that data remain within EU boundaries. For strict data residency, avoid any configuration that places persistent data in a region outside the EU.
- ✓
Select a Google Cloud region located in the EU
Why this is correct
Choosing a Google Cloud region in the EU, such as europe-west1 (Belgium) or europe-west4 (Netherlands), ensures that all customer data stored at rest and processed within that region remains inside the EU's jurisdiction. This is the fundamental control for data residency, and you can further use regional managed services (e.g., Cloud SQL, GKE regional) while keeping zones within that region for availability. This directly satisfies the regulatory requirement.
- ✗
Enable data encryption at rest
Why it's wrong here
Enabling encryption at rest, whether with Google-managed or customer-managed keys, protects data confidentiality but has no effect on the physical location where the encrypted data is stored. The ciphertext could still be written to a region outside the EU, making the deployment non-compliant. Because Google Cloud already encrypts all data at rest by default, this action adds no residency guarantee and is therefore not a valid compliance measure.
- ✗
Use Cloud VPN for connectivity
Why it's wrong here
Cloud VPN establishes an encrypted tunnel over the internet between your on-premises network and a Google Cloud VPC, securing traffic in transit, but it does not determine or alter the geographic region where your data is stored at rest. It only changes the network path; the underlying services remain pinned to whatever region they were provisioned in. Therefore, using Cloud VPN cannot keep data inside the EU if the chosen region is elsewhere, nor does it add any residency benefit.
Go deeper
Related to this question
Learn chapter
Data Types and Analytics Workloads
Key term
Data
Data is raw, unprocessed information, like numbers, words, or measurements, that can be stored, processed, and analyzed by computers.
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
About these practice questions
Courseiva writes every GCDL question from scratch — 848 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.