Courseiva

Cloud Digital Leader Why Cloud Technology Can Transform Business Practice Question

A financial services company must comply with strict data residency regulations. They need to store customer data in a specific geographic region and ensure it never leaves that region. Which Google Cloud feature should they use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Organization Policy with location restrictions

Organization Policy with location restrictions allows admins to restrict resource creation to specific regions, preventing data from being stored elsewhere. VPC Service Controls provide data exfiltration prevention but do not restrict region. IAM controls access, not location. Cloud KMS manages keys.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VPC Service Controls

    Why it's wrong here

    VPC Service Controls create security perimeters around Google Cloud services, using context-aware boundaries to prevent data exfiltration. However, they operate at the service/API level and do not constrain where resources are physically provisioned; a project inside a perimeter can still create resources in any region unless location is separately constrained. Therefore, VPC Service Controls alone cannot enforce data residency requirements.

  • ✗

    Cloud IAM

    Why it's wrong here

    Cloud IAM manages who can perform actions on resources by assigning roles and permissions, but it has no concept of data location or region constraints. IAM can grant or deny the ability to create resources, yet it cannot specify that those resources must be provisioned in a particular region or prohibit storage in other geographic areas. This makes IAM ineffective for enforcing data residency.

  • ✓

    Organization Policy with location restrictions

    Why this is correct

    Organization policies using the `constraints/gcp.resource-locations` constraint (Resource Location Restriction) allow administrators to define an allowlist of regions where resources may be created. This policy is inherited across folders and projects and is enforced at resource creation time, so services such as Compute Engine, GKE, and Cloud Storage can only deploy in approved locations. This directly enforces data residency by blocking resource creation outside specified regions.

  • ✗

    Cloud Key Management Service

    Why it's wrong here

    Cloud KMS provides centralized management of encryption keys, including customer-managed encryption keys (CMEK), but it does not control where data is stored or which regions are used for resource deployment. Even when keys are stored in a specific region, the encrypted data and workloads that use those keys can reside in entirely different locations. Therefore, Cloud KMS addresses encryption key governance, not geographic data residency.

About these practice questions

This GCDL question is part of Courseiva's 848-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.