CASE STUDY: TrendWear Apparel
Company Overview:
TrendWear Apparel is a global clothing retailer with an e-commerce platform and 500 physical stores.
Current Technical Environment:
Business Requirements:
Executive Statements:
Technical Requirements:
Constraints:
QUESTION:
Based on the CTO's requirement for a consistent management plane across on-premises and the cloud, and the need to modernize to microservices while keeping the mainframe, which compute architecture should you recommend?
GCP PCA · Question 08 · Domain 3: Designing for Security and Compliance
CASE STUDY: TrendWear Apparel
Company Overview:
TrendWear Apparel is a global clothing retailer with an e-commerce platform and 500 physical stores.
Current Technical Environment:
Business Requirements:
Executive Statements:
Technical Requirements:
Constraints:
QUESTION:
To meet the PCI-DSS compliance requirement, the security team wants to ensure that raw credit card numbers are never stored in the cloud databases. How should you design the data ingestion pipeline?
Answer options:
Encrypt the database using Customer-Managed Encryption Keys (CMEK).
Use the Cloud Data Loss Prevention (DLP) API to tokenize credit card numbers before they are written to the database.
Store the credit card numbers in Secret Manager.
Configure VPC Service Controls to block external access to the database.
50 questions · hints · full answers · grading