GCP PCA · Question 44 · Domain 3: Designing for Security and Compliance
Your company is building a payment processing system on GCP that must comply with PCI-DSS. Which THREE architectural practices should you implement to help achieve and maintain compliance? (Select THREE)
Answer options:
Use Cloud Data Loss Prevention (DLP) to tokenize Primary Account Numbers (PAN) before storing them.
Store all credit card data in a single, centralized Cloud SQL database accessible by all developers.
Implement VPC Service Controls to create a secure perimeter around the projects processing payment data.
Disable Cloud Audit Logs to improve database performance.
Apply the principle of least privilege using custom IAM roles for service accounts.
Use HTTP instead of HTTPS for internal microservice communication to reduce latency.
50 questions · hints · full answers · grading