Courseiva
Trust and security with Google CloudmediumMultiple ChoiceObjective-mapped

Cloud Digital Leader Trust and security with Google Cloud Practice Question

A company uses Google Cloud and has a compliance requirement to store certain data only within the European Union and ensure it cannot be accessed from outside the EU, even by Google operations personnel. Which Google Cloud offering specifically addresses this level of data sovereignty?

⚠ Common exam trap

Many candidates confuse geographic storage (selecting EU regions) with full data sovereignty, failing to realize that personnel access controls are required to prevent internal Google staff from accessing data from outside the EU.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Sovereign Controls offerings (e.g., T-Systems Sovereign Cloud) or Assured Workloads with data residency and personnel access controls.

Sovereign Controls offerings (such as T-Systems Sovereign Cloud) and Assured Workloads with data residency and personnel access controls are specifically designed to meet strict data sovereignty requirements. These solutions ensure that data remains within the EU and that Google operations personnel cannot access it, addressing both geographic storage and access restrictions mandated by compliance frameworks like GDPR.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Selecting EU regions for all resources in the Cloud Console.

    Why it's wrong here

    Choosing EU regions in the Cloud Console only pins down where data is at rest. It does not prevent Google operations personnel from having access under the standard Google Cloud support model, nor does it create a contractual data sovereignty commitment beyond ordinary data residency terms. Regulatory frameworks often require explicit personnel-access restrictions and audit rights, not just storage location.

  • Sovereign Controls offerings (e.g., T-Systems Sovereign Cloud) or Assured Workloads with data residency and personnel access controls.

    Why this is correct

    Google's sovereign offerings, including Assured Workloads and partner-based solutions like T-Systems Sovereign Cloud, combine EU data residency, restricted personnel access, and contractual jurisdictional commitments. Assured Workloads enforces org policy constraints and controls for compliance, while Sovereign Cloud runs on dedicated infrastructure with EU-based operations staff. These are the technically appropriate choices when the requirement is full algorithmic and operational sovereignty, not merely network or storage controls.

  • VPC Service Controls — they prevent data from leaving the VPC boundary.

    Why it's wrong here

    VPC Service Controls uses identity and context-aware perimeters to limit data movement between Google Cloud services and projects, helping prevent unauthorized exfiltration. However, it operates within the Google Cloud control plane and does not stop Google personnel, such as site reliability engineers, from performing support or maintenance under standard provisions. It also offers no contractual EU-only residency guarantees or local jurisdictional protections for sovereign workloads.

  • Cloud Armor — it blocks requests originating from outside the EU.

    Why it's wrong here

    Cloud Armor enforces network-layer policies by blocking requests from non-EU IP ranges, but this only affects who can initiate traffic. It does nothing to keep data inside EU boundaries once stored or processed, and it does not restrict Google operations staff. Sovereignty compliance also requires documented guarantees about data handling by cloud provider employees, which an edge security policy cannot provide.

About these practice questions

This GCDL question is part of Courseiva's 829-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.