mediumMultiple SelectObjective-mapped
PCSE Practice Question: Migrating to Google Cloud and needs to comply…
A company is migrating to Google Cloud and needs to comply with the Health Insurance Portability and Accountability Act (HIPAA). They plan to use Cloud SQL for MySQL and Cloud Storage. Which TWO actions must they take to ensure HIPAA compliance?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sign a Business Associate Agreement (BAA) with Google Cloud.
To achieve HIPAA compliance on Google Cloud, the organization must sign a Business Associate Agreement (BAA) with Google, which contractually establishes Google as a business associate. Additionally, encryption at rest must be enabled for Cloud SQL and Cloud Storage to protect protected health information (PHI). Option B is incorrect because disabling automatic backups is not a HIPAA requirement and could compromise data availability. Option D is incorrect because VPC Service Controls help prevent data exfiltration but are not specifically mandated by HIPAA. Option E is incorrect because customer-managed encryption keys (CMEK) are optional; Google's default encryption at rest satisfies HIPAA requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Sign a Business Associate Agreement (BAA) with Google Cloud.
Why this is correct
A BAA is required for any HIPAA-covered entity using Google Cloud services.
- ✗
Disable automatic backups to prevent exposure of protected health information (PHI).
Why it's wrong here
Backups are important for data durability; HIPAA does not require disabling them.
- ✓
Enable encryption at rest for Cloud SQL and Cloud Storage.
Why this is correct
HIPAA requires encryption of PHI at rest.
- ✗
Implement VPC Service Controls to create a perimeter around the projects.
Why it's wrong here
VPC Service Controls are a security best practice but not a HIPAA requirement.
- ✗
Use customer-managed encryption keys (CMEK) for all services.
Why it's wrong here
CMEK is optional; default Google-managed encryption meets HIPAA requirements.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCSE question from scratch — 960 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCSE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCSE exam.