Cloud Digital Leader Why Cloud Technology Can Transform Business Practice Question
A financial services company must comply with strict data residency regulations. They need to store customer data in a specific geographic region and ensure it never leaves that region. Which Google Cloud feature should they use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Organization Policy with location restrictions
Organization Policy with location restrictions allows admins to restrict resource creation to specific regions, preventing data from being stored elsewhere. VPC Service Controls provide data exfiltration prevention but do not restrict region. IAM controls access, not location. Cloud KMS manages keys.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
VPC Service Controls
Why it's wrong here
VPC Service Controls create security perimeters around Google Cloud services, using context-aware boundaries to prevent data exfiltration. However, they operate at the service/API level and do not constrain where resources are physically provisioned; a project inside a perimeter can still create resources in any region unless location is separately constrained. Therefore, VPC Service Controls alone cannot enforce data residency requirements.
- ✗
Cloud IAM
Why it's wrong here
Cloud IAM manages who can perform actions on resources by assigning roles and permissions, but it has no concept of data location or region constraints. IAM can grant or deny the ability to create resources, yet it cannot specify that those resources must be provisioned in a particular region or prohibit storage in other geographic areas. This makes IAM ineffective for enforcing data residency.
- ✓
Organization Policy with location restrictions
Why this is correct
Organization policies using the `constraints/gcp.resource-locations` constraint (Resource Location Restriction) allow administrators to define an allowlist of regions where resources may be created. This policy is inherited across folders and projects and is enforced at resource creation time, so services such as Compute Engine, GKE, and Cloud Storage can only deploy in approved locations. This directly enforces data residency by blocking resource creation outside specified regions.
- ✗
Cloud Key Management Service
Why it's wrong here
Cloud KMS provides centralized management of encryption keys, including customer-managed encryption keys (CMEK), but it does not control where data is stored or which regions are used for resource deployment. Even when keys are stored in a specific region, the encrypted data and workloads that use those keys can reside in entirely different locations. Therefore, Cloud KMS addresses encryption key governance, not geographic data residency.
Go deeper
Related to this question
Learn chapter
Building a Data-Driven Culture
Key term
Google Cloud
Google Cloud is a suite of cloud computing services offered by Google that provides infrastructure, platform, and software solutions over the internet.
Key term
Region
A region is a distinct geographic location where a cloud provider operates multiple data centers that are connected by low-latency networks and provide cloud services.
About these practice questions
This GCDL question is part of Courseiva's 848-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.