CASE STUDY: CareData Health
Company Overview:
CareData Health is a large healthcare provider network operating 50 hospitals. They manage petabytes of patient records, medical imaging, and telemetry data.
Current Technical Environment:
Business Requirements:
Executive Statements:
Technical Requirements:
Constraints:
QUESTION:
To meet the CISO's requirement of preventing unauthorized data exfiltration from the centralized data lake (BigQuery and Cloud Storage), which security control should you implement?
GCP PCA · Question 12 · Domain 3: Designing for Security and Compliance
CASE STUDY: CareData Health
Company Overview:
CareData Health is a large healthcare provider network operating 50 hospitals. They manage petabytes of patient records, medical imaging, and telemetry data.
Current Technical Environment:
Business Requirements:
Executive Statements:
Technical Requirements:
Constraints:
QUESTION:
To satisfy the technical requirement for encryption using keys managed by CareData, how should you configure encryption for the Cloud Storage buckets and BigQuery datasets?
Answer options:
Rely on Google's default encryption at rest.
Implement Customer-Managed Encryption Keys (CMEK) using Cloud Key Management Service (KMS).
Implement Customer-Supplied Encryption Keys (CSEK) by storing the keys on an on-premises HSM.
Encrypt the data within the application layer before sending it to GCP.
50 questions · hints · full answers · grading