A company is deploying a workload that must comply with FedRAMP High. They are using Assured Workloads. Which TWO controls are automatically enabled when they select the FEDRAMP_HIGH regime?
Trap 1: Google personnel access restrictions
Google personnel access restrictions is an optional control, not automatically enabled; it requires manual configuration.
Trap 2: VPC Service Controls
VPC Service Controls are not automatically enabled; they must be configured separately.
Trap 3: Cloud Armor WAF
Cloud Armor WAF is not automatically enforced by Assured Workloads.
- A
Google personnel access restrictions
Why wrong: Google personnel access restrictions is an optional control, not automatically enabled; it requires manual configuration.
- B
Resource location restrictions (data must remain in the US)
Resource location restrictions are automatically enforced to ensure data residency in the US for FedRAMP High.
- C
VPC Service Controls
Why wrong: VPC Service Controls are not automatically enabled; they must be configured separately.
- D
Compliance monitoring (continuous monitoring of compliance drift)
Compliance monitoring is automatically enabled to provide continuous compliance drift detection.
- E
Cloud Armor WAF
Why wrong: Cloud Armor WAF is not automatically enforced by Assured Workloads.