Courseiva

Google PCA Design for security and compliance Practice Question

A company is designing a data processing pipeline in Google Cloud that must be HIPAA compliant. Which three security features should they implement? (Choose three.)

⚠ Common exam trap

A common mix-up: candidates confuse data classification tools like DLP with mandatory security controls, or mistake performance features like Cloud CDN for compliance requirements, when HIPAA specifically requires encryption, access controls, and audit trails.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Encrypt data in transit using TLS

Encrypting data in transit using TLS is a mandatory security control for HIPAA compliance because it protects electronic protected health information (ePHI) from interception during transmission over networks. TLS 1.2 or higher ensures that data moving between clients, services, and Google Cloud endpoints is encrypted, meeting the HIPAA Security Rule requirement for integrity and confidentiality of ePHI in transit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Encrypt data in transit using TLS

    Why this is correct

    Required by HIPAA for data in transit.

  • ✗

    Enable Data Loss Prevention (DLP) for data classification

    Why it's wrong here

    DLP is helpful but not a required HIPAA security control.

  • ✗

    Use Cloud CDN for faster delivery

    Why it's wrong here

    CDN is for performance, not security.

  • ✓

    Implement VPC Service Controls to prevent data exfiltration

    Why this is correct

    VPC Service Controls help enforce access controls and prevent data exfiltration, important for HIPAA.

  • ✓

    Use Cloud HSM for encryption keys

    Why this is correct

    Provides customer-managed HSM-backed keys for encryption at rest, a common compliance requirement.

About these practice questions

This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.