Courseiva

Cloud Digital Leader Why cloud technology is transforming business Practice Question

A financial services company must comply with strict data residency regulations. Which cloud feature helps meet compliance requirements?

⚠ Common exam trap

A common mistake is confusing data residency (where data is stored) with data encryption (who can read it). Even with customer-managed keys, data may reside in any region, so encryption alone does not satisfy residency requirements.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data location controls

Data location controls (Option A) allow explicit geographic restrictions, directly meeting data residency requirements. Customer-managed encryption keys (Option E) address data confidentiality and access control, not where data resides. The other options are irrelevant or misleading.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Data location controls

    Why this is correct

    Data location controls are a fundamental compliance feature, as they allow an organization to explicitly choose the geographic region where its data is stored. This ensures data residency and sovereignty requirements are met, such as those imposed by GDPR, PCI-DSS, or local banking regulations. By restricting data to approved jurisdictions, enterprises can avoid violating laws that mandate data stay within national borders, and auditors can verify that data never leaves those boundaries.

  • ✗

    Open source software

    Why it's wrong here

    Open source software alone cannot satisfy regulatory compliance because it is a software development and licensing model, not a set of operational controls. Compliance frameworks require specific measures like access controls, encryption, audit logging, and incident response procedures, none of which are inherently present in open source code. Furthermore, open source components may have vulnerabilities or unclear provenance, and organizations must still configure and manage them to meet regulatory standards, so they provide no automatic compliance benefit.

  • ✗

    Public internet access

    Why it's wrong here

    Public internet access directly undermines compliance by exposing sensitive data and systems to untrusted networks, increasing the risk of unauthorized access, interception, and attacks. Compliance frameworks typically mandate secure connectivity, such as private networks, VPNs, or encrypted channels, and require strict network segmentation to protect data in transit. Allowing public internet access introduces attack vectors that violate confidentiality and integrity requirements, making it a threat to compliance rather than a feature.

  • ✗

    Single data center footprint

    Why it's wrong here

    A single data center footprint creates a single point of failure, which is contrary to the resilience and availability requirements of most compliance regulations. Compliance frameworks, such as those in financial services and healthcare, often demand redundancy, failover capability, and disaster recovery to ensure business continuity and data protection. Additionally, relying on one location does not help with data residency, as it may not offer the geographic diversity needed to keep data within specific jurisdictions while maintaining uptime, so it is not a valid compliance control.

  • ✗

    Customer-managed encryption keys

    Why it's wrong here

    Customer-managed encryption keys provide a robust compliance mechanism by giving organizations full control over their cryptographic keys, including generation, rotation, and revocation. This enables strict auditability of key usage and ensures that only authorized parties can access encrypted data, satisfying regulatory mandates that require customer control over cryptographic material. With CMEK, enterprises can also enforce separation of duties, as cloud providers cannot access plaintext data without the customer's explicit action, which is essential for many compliance frameworks.

About these practice questions

Courseiva writes every GCDL question from scratch — 848 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.