CASE STUDY: ShopGlobal
Company Overview:
ShopGlobal is an international e-commerce retailer. They are preparing for their largest annual sales event (Black Friday) and want to migrate off their aging on-premises infrastructure.
Current Technical Environment:
Business Requirements:
Executive Statements:
Technical Requirements:
Constraints:
QUESTION:
Given the 4-month timeline and the CTO's constraints, which migration strategy should you recommend for the VMware environment?
GCP PCA · Question 08 · Compliance Design
CASE STUDY: ShopGlobal
Company Overview:
ShopGlobal is an international e-commerce retailer. They are preparing for their largest annual sales event (Black Friday) and want to migrate off their aging on-premises infrastructure.
Current Technical Environment:
Business Requirements:
Executive Statements:
Technical Requirements:
Constraints:
QUESTION:
To ensure PCI-DSS compliance for payment processing in the new cloud environment, which combination of GCP security controls should you implement?
Answer options:
Encrypt all data at rest using Google-managed encryption keys (GMEK) and disable external IP addresses on all VMs.
Implement VPC Service Controls to create a secure perimeter, use Cloud DLP to tokenize credit card data, and enable Cloud Audit Logs.
Deploy a third-party Next-Generation Firewall (NGFW) from the Google Cloud Marketplace and route all traffic through it.
Store all payment data in a separate GCP project and use VPC Network Peering to connect it to the web servers.
50 questions · hints · full answers · grading