Courseiva

PCSE · domain

Supporting Compliance Requirements

Practise Google Professional Cloud Security Engineer Supporting Compliance Requirements practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

73 questions16 easy37 medium20 hard

Focused practice

Practice Supporting Compliance Requirements questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Supporting Compliance Requirements

Supporting Compliance Requirements questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Supporting Compliance Requirements exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Supporting Compliance Requirements questions (73)

Click any question to see the full explanation, or start a practice session above.

1

A company is implementing GDPR compliance and wants to ensure that personal data is pseudonymized in BigQuery. They plan to use Cloud DLP to tokenize data before loading. Which approach should they take to minimize changes to existing SQL queries?

Hard
2

A company needs to store financial records for 7 years to meet regulatory requirements. They want to ensure that once written, the records cannot be modified or deleted by anyone, including cloud administrators. Which Cloud Storage feature should they enable?

Medium
3

A company wants to enforce that all Cloud Storage buckets created in their organization have a retention policy for compliance. If a bucket is created without a retention policy, it should be automatically remediated. Which approach should they use?

Hard
4

A financial institution is required to retain records of all transactions for 7 years under regulatory compliance. They are using Cloud Storage for archive data and need to ensure that objects cannot be deleted or overwritten during the retention period. Which feature should they use?

Easy
5

A healthcare company stores de-identified patient data in BigQuery for analytics. They must comply with HIPAA and ensure that re-identification is not possible. They also need to be able to join data on a per-patient basis for longitudinal studies. Which TWO strategies should they implement? (Choose 2)

Hard
6

A healthcare organization is required to protect Protected Health Information (PHI) stored in Cloud Storage. They want to automatically detect and redact PHI before storing it. Which Google Cloud service should they use?

Medium
7

A company is migrating a PCI DSS-compliant application to GCP. They need to meet encryption requirements for cardholder data. Which TWO options satisfy PCI DSS encryption requirements? (Choose two.)

Medium
8

A company is using Assured Workloads to meet EU data residency requirements (EU_REGIONS_AND_SUPPORT). They want to monitor compliance drift when changes are made to the environment. Which service should they use?

Hard
9

A financial institution is deploying a payment application on GKE that must comply with PCI DSS. They need to isolate the cardholder data environment (CDE) from other workloads and ensure only authorized services can communicate. Which combination of controls should they implement?

Hard
10

A company using Assured Workloads with the FedRAMP High compliance regime wants to monitor for configuration changes that could cause the environment to become non-compliant. Which tool should they use to detect compliance drift?

Hard
11

A company is using Assured Workloads to enforce FEDRAMP_HIGH compliance. They need to ensure that only US-based personnel from Google can access their data. Which configuration setting within the Assured Workloads folder should they enable?

Hard
12

A company has deployed an application in Assured Workloads with the FEDRAMP_HIGH compliance regime. They need to ensure that Google Cloud personnel cannot access their data. Which additional control should they enable?

Hard
13

A company wants to encrypt data at rest in Cloud Storage using their own keys. Which Cloud service should they use to manage these keys?

Easy
14

A company processes personal data of European Union residents on GCP. They need to ensure that data processing is limited to specific purposes and that data subjects can exercise their rights (access, rectification, erasure). Which actions should they take to comply with GDPR?

Medium
15

Which Google Cloud compliance certification is most relevant for a company that processes credit card transactions and needs to demonstrate secure handling of cardholder data?

Easy
16

A company handles Controlled Unclassified Information (CUI) and needs to deploy a workload that complies with ITAR (International Traffic in Arms Regulations). They plan to use Assured Workloads. Which compliance regime should they select when creating the Assured Workloads folder?

Medium
17

A company uses Assured Workloads with the FEDRAMP_HIGH regime. They want to enforce resource location restrictions and restrict Google personnel access. Which TWO capabilities should they enable? (Choose two.)

Hard
18

A company is designing a PCI DSS-compliant environment on Google Cloud. They need to isolate the cardholder data environment (CDE) and log all access to it. Which THREE actions should they take? (Choose 3)

Medium
19

A multinational company is using Assured Workloads to meet EU_Regions_and_Support compliance. They need to ensure that only EU-based Google personnel can access the customer's data for support purposes. Which configuration should they enable?

Hard
20

A company is deploying a PCI DSS-compliant application on Google Cloud. They need to ensure that the Cardholder Data Environment (CDE) is isolated from other resources and that only authorized services can communicate with it. Which combination of controls should they implement?

Hard
21

A company subject to EU GDPR must implement the right to erasure (right to be forgotten) for personal data stored in BigQuery audit logs. The logs include query text that may contain personally identifiable information (PII). What is the correct approach to anonymize or delete PII from BigQuery audit logs?

Hard
22

Which Google Cloud service can automatically classify and de-identify sensitive data such as credit card numbers and health records before it is stored in Cloud Storage?

Easy
23

A company must implement a data retention policy that prevents any modification or deletion of stored log files for 5 years. Which Cloud Storage feature should they use?

Easy
24

A financial institution needs to comply with GDPR data subject rights. They must ensure that personal data in BigQuery can be anonymized for analytics while still allowing joins on pseudonymized identifiers. Which THREE services or features should they consider? (Choose 3)

Hard
25

A company using BigQuery for analytics needs to comply with the right to be forgotten (erasure) under GDPR. A data subject requests deletion of their personal data. What is the correct approach to delete data from BigQuery audit logs that contain the data subject's information?

Hard
26

A company needs to comply with GDPR requirements for data subject rights. They must be able to provide data subjects with access to their personal data and rectify inaccuracies. Which TWO Google Cloud services can assist with these requirements? (Choose two.)

Easy
27

An organization handles ITAR-controlled data and must restrict Google personnel access to the underlying infrastructure. Which Google Cloud product should they use to enforce this restriction?

Medium
28

A company subject to GDPR receives a request from a data subject to delete all personal data from BigQuery audit logs. The logs contain query execution details with user identifiers. How can the company comply with the right to erasure (right to be forgotten)?

Medium
29

A company using Google Cloud wants to conduct a penetration test on their infrastructure. According to Google's acceptable use policy, what must they do before testing?

Easy
30

A data subject requests the deletion of their personal data from a Google Cloud project under GDPR. This data is stored in BigQuery audit logs that are retained for 30 days by default. What is the correct approach to fulfill this request?

Medium
31

A company wants to ensure that data stored in Cloud Storage is encrypted at rest using keys that they generate and manage on-premises. Which encryption method should they use?

Easy
32

Which of the following is a customer responsibility under the Google Cloud shared responsibility model?

Easy
33

A company needs to implement data pseudonymisation to comply with GDPR. They are using BigQuery for analytics. Which TWO services can help them pseudonymise data in transit before it enters BigQuery?

Medium
34

An organization subject to GDPR receives a data subject request for erasure ('right to be forgotten'). The data subject's information is stored in BigQuery audit logs. What is the implication for the audit logs, and what should the organization do?

Medium
35

A multinational company must comply with GDPR and needs to ensure that personal data is processed in a manner that respects data subject rights. Which TWO of the following are required under GDPR? (Choose 2)

Medium
36

A healthcare organization needs to ensure that all access to ePHI in Cloud SQL is logged for HIPAA compliance. They have enabled audit logs. What additional step is required to ensure logs are retained for at least one year?

Medium
37

A company needs to retain audit logs for 7 years to meet compliance requirements. By default, Cloud Audit Logs are retained for 30 days. What should they do to retain the logs for 7 years?

Medium
38

A company is using BigQuery to store analytics data and wants to ensure that data is retained for exactly 365 days after ingestion, then automatically deleted. How can they achieve this with minimal operational overhead?

Medium
39

A government contractor needs to deploy a workload on Google Cloud that complies with FedRAMP High and ITAR (International Traffic in Arms Regulations). They require that Google personnel cannot access the infrastructure and that data residency is restricted to the United States. Which Google Cloud solution should they use?

Medium
40

An organization is using Assured Workloads to enforce ITAR compliance. They need to ensure that all resources are deployed in specific US regions and that Google personnel access is restricted. They also want to monitor for any configuration changes that violate compliance policies. Which service should they use for monitoring compliance drift?

Hard
41

A company is subject to SOC 2 compliance and wants to demonstrate that they have implemented proper access controls on Google Cloud. Which TWO IAM best practices should they follow? (Choose two.)

Easy
42

A security engineer needs to run a penetration test against their Google Cloud environment. According to Google's Acceptable Use Policy, which of the following is true regarding penetration testing?

Medium
43

A company needs to store audit logs for a minimum of 5 years to meet compliance requirements. Cloud Logging retains logs for 30 days by default. Which approach should they take?

Medium
44

Which Google Cloud service is specifically designed to help customers meet compliance requirements by creating a folder with pre-defined organization policies, resource location restrictions, and access controls?

Easy
45

A security engineer needs to audit changes to IAM policies across their Google Cloud organization. Which audit log type should they enable to capture IAM policy changes?

Medium
46

A healthcare organization is migrating to Google Cloud and needs to store Protected Health Information (PHI) in Cloud Storage. They have signed a Business Associate Agreement (BAA) with Google. Which additional step is REQUIRED to ensure HIPAA compliance for the data stored?

Medium
47

A financial institution must store audit logs for 7 years to comply with PCI DSS requirements. By default, Cloud Audit Logs are retained for 30 days. What is the most cost-effective way to retain audit logs for 7 years?

Medium
48

Which Google Cloud service provides the ability to enforce data retention policies on Cloud Storage objects to prevent deletion or modification for a specified duration?

Easy
49

A company is subject to PCI DSS and needs to protect a web application that processes credit card data. They want to block common web attacks such as SQL injection and cross-site scripting (XSS). Which Google Cloud service should they use?

Medium
50

A multinational corporation uses Google Cloud and must comply with GDPR. They want to process personal data for a new purpose that was not originally disclosed to data subjects. What is the correct course of action under GDPR?

Hard
51

A government contractor needs to deploy workloads on GCP that meet FedRAMP High baseline requirements. They want to enforce resource location restrictions and access controls for Google personnel. Which product should they use?

Medium
52

A company is using Assured Workloads with the FEDRAMP_HIGH regime. They need to restrict where resources can be created and monitor for compliance violations. Which TWO settings should they configure? (Choose 2)

Medium
53

A company is deploying a PCI DSS-compliant application on Google Cloud. They need to ensure that the cardholder data environment (CDE) is isolated and that only authorized services can communicate. Which TWO services should they use? (Choose 2)

Medium
54

A company that stores protected health information (PHI) in Google Cloud wants to run a BigQuery query to identify and classify sensitive data such as patient names and social security numbers. Which Google Cloud service should they use?

Easy
55

An organization must comply with ITAR regulations. They use Assured Workloads with the ITAR regime. Which THREE controls are automatically enforced by this regime? (Choose three.)

Hard
56

A company subject to PCI DSS is building a cardholder data environment (CDE) on Google Cloud. They need to encrypt cardholder data at rest and in transit. Which THREE measures should they implement? (Choose three.)

Medium
57

A healthcare organization is migrating to Google Cloud and needs to store Protected Health Information (PHI) while maintaining HIPAA compliance. They have executed a Business Associate Agreement (BAA) with Google. Which additional step is required to ensure that PHI is properly classified and protected?

Medium
58

A company is required to perform penetration testing on their Google Cloud infrastructure. According to Google Cloud's policy, which statement is true regarding penetration testing?

Medium
59

A company needs to retain critical financial records for 7 years to comply with SEC regulations. They choose to store the records in Cloud Storage. Which feature should they enable to ensure the records cannot be deleted or overwritten before the retention period expires?

Easy
60

A company needs to ensure that all data stored in Cloud Storage is encrypted at rest using keys that they generate and manage themselves. They also need to rotate the keys every 90 days. Which encryption option should they use?

Medium
61

A healthcare organization is migrating workloads to Google Cloud and needs to process Protected Health Information (PHI) under HIPAA. Which step is required before storing PHI in any GCP service?

Medium
62

A company is designing a PCI DSS-compliant architecture on Google Cloud. They need to ensure that the cardholder data environment (CDE) is isolated from other environments and that all access to the CDE is logged. Which THREE controls should they implement? (Choose three.)

Hard
63

A company must process credit card transactions on Google Cloud and achieve PCI DSS compliance. They want to minimize the scope of the cardholder data environment (CDE). Which architectural approach should they take?

Hard
64

An organization wants to run a penetration test on their Google Cloud environment to validate security controls. According to Google's Acceptable Use Policy, which of the following is true regarding penetration testing?

Medium
65

A company processes healthcare data and has signed a BAA with Google Cloud. They need to implement controls for HIPAA compliance. Which THREE actions should they take? (Choose three.)

Medium
66

A company is implementing PCI DSS compliance on Google Cloud. They need to ensure that cardholder data is encrypted in transit and at rest. Which TWO encryption controls are required by PCI DSS?

Medium
67

A financial institution is deploying a PCI DSS-compliant cardholder data environment (CDE) on Google Cloud. They need to segment the CDE from other environments and restrict data egress from the CDE. Which two services should they use together? (Choose the best combination.)

Hard
68

A security engineer wants to test a web application hosted on Compute Engine for vulnerabilities. According to Google Cloud's Acceptable Use Policy, which of the following is true regarding penetration testing?

Medium
69

A security team wants to monitor for compliance drift in an Assured Workloads folder that enforces FedRAMP High controls. Which Google Cloud service should they use to detect violations of organization policies?

Easy
70

A healthcare organization is migrating PHI workloads to Google Cloud and needs to encrypt data at rest with keys that are generated and managed within their own on-premises hardware security module (HSM). Which encryption approach should they use?

Medium
71

Which Google Cloud compliance certification requires the customer to sign a Business Associate Agreement (BAA) with Google?

Easy
72

A company is implementing a HIPAA-compliant environment on Google Cloud. They need to ensure that all access to protected health information (PHI) is logged and monitored. Which TWO steps should they take? (Choose two.)

Medium
73

A financial institution is deploying a PCI DSS-compliant web application on Google Cloud. They need to isolate the cardholder data environment (CDE) from other environments and protect the web application against common web attacks. Which combination of services meets these requirements?

Medium

Frequently asked questions

What does the Supporting Compliance Requirements domain cover on the PCSE exam?
Supporting Compliance Requirements questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 73 Supporting Compliance Requirements questions in the PCSE question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Supporting Compliance Requirements questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
Google Professional Cloud Security Engineer PCSE Supporting Compliance Requirements Practice Questions