Courseiva
mediumMultiple SelectObjective-mapped

PCSE Practice Question: Migrating to Google Cloud and needs to comply…

A company is migrating to Google Cloud and needs to comply with the Health Insurance Portability and Accountability Act (HIPAA). They plan to use Cloud SQL for MySQL and Cloud Storage. Which TWO actions must they take to ensure HIPAA compliance?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Sign a Business Associate Agreement (BAA) with Google Cloud.

To achieve HIPAA compliance on Google Cloud, the organization must sign a Business Associate Agreement (BAA) with Google, which contractually establishes Google as a business associate. Additionally, encryption at rest must be enabled for Cloud SQL and Cloud Storage to protect protected health information (PHI). Option B is incorrect because disabling automatic backups is not a HIPAA requirement and could compromise data availability. Option D is incorrect because VPC Service Controls help prevent data exfiltration but are not specifically mandated by HIPAA. Option E is incorrect because customer-managed encryption keys (CMEK) are optional; Google's default encryption at rest satisfies HIPAA requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Sign a Business Associate Agreement (BAA) with Google Cloud.

    Why this is correct

    A BAA is required for any HIPAA-covered entity using Google Cloud services.

  • Disable automatic backups to prevent exposure of protected health information (PHI).

    Why it's wrong here

    Backups are important for data durability; HIPAA does not require disabling them.

  • Enable encryption at rest for Cloud SQL and Cloud Storage.

    Why this is correct

    HIPAA requires encryption of PHI at rest.

  • Implement VPC Service Controls to create a perimeter around the projects.

    Why it's wrong here

    VPC Service Controls are a security best practice but not a HIPAA requirement.

  • Use customer-managed encryption keys (CMEK) for all services.

    Why it's wrong here

    CMEK is optional; default Google-managed encryption meets HIPAA requirements.

About these practice questions

Courseiva writes every PCSE question from scratch — 960 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCSE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCSE exam.