CASE STUDY: CareData Health
Company Overview:
CareData Health is a large healthcare provider network operating 50 hospitals. They manage petabytes of patient records, medical imaging, and telemetry data.
Current Technical Environment:
Business Requirements:
Executive Statements:
Technical Requirements:
Constraints:
QUESTION:
To meet the CISO's requirement of preventing unauthorized data exfiltration from the centralized data lake (BigQuery and Cloud Storage), which security control should you implement?
GCP PCA · Question 15 · Domain 4: Analyzing and Optimizing Technical and Business Processes
CASE STUDY: CareData Health
Company Overview:
CareData Health is a large healthcare provider network operating 50 hospitals. They manage petabytes of patient records, medical imaging, and telemetry data.
Current Technical Environment:
Business Requirements:
Executive Statements:
Technical Requirements:
Constraints:
QUESTION:
The DPO mandates physical separation of EU and US data. How should you design the BigQuery architecture to ensure compliance while minimizing operational overhead?
Answer options:
Deploy a single BigQuery dataset in the US and use row-level security to hide US data from EU users.
Create separate BigQuery datasets in the 'EU' multi-region and the 'US' multi-region, and configure IAM permissions to restrict access.
Create two separate GCP Organizations, one for the EU and one for the US.
Use Cloud Spanner instead of BigQuery, as Spanner automatically pins data to specific regions based on the user's IP address.
50 questions · hints · full answers · grading