For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeGCP Professional Cloud ArchitectGCP Professional Cloud Architect Practice Exam 7Question 08
    Hard1 markMultiple Choice
    Subtask 3.2: Compliance DesignPCI-DSSSecurityVPC Service ControlsCloud DLP
    This question is part of a case study — click to read the full scenario(Case 06)

    CASE STUDY: ShopGlobal

    Company Overview:
    ShopGlobal is an international e-commerce retailer. They are preparing for their largest annual sales event (Black Friday) and want to migrate off their aging on-premises infrastructure.

    Current Technical Environment:

    • 3 on-premises data centers (US-East, US-West, EU-Central).
    • VMware vSphere environment with 500 VMs.
    • Monolithic Java application running on Tomcat.
    • Oracle RAC database for transactions.
    • 50 TB of product images on SAN storage.

    Business Requirements:

    • Ensure 100% availability during the upcoming holiday season.
    • Modernize the application architecture over the next 3 years.
    • Reduce capital expenditure (CapEx) by shifting to an OpEx model.

    Executive Statements:

    • CEO: "Downtime during Black Friday costs us $1M per hour. We need bulletproof reliability."
    • CFO: "We want to stop buying hardware. Move everything to a pay-as-you-go model."
    • CTO: "We want to eventually move to microservices, but we don't have time to rewrite the app before the holidays."

    Technical Requirements:

    • Migrate the existing VMs to the cloud with minimal changes initially.
    • Implement a global CDN for product images to reduce latency.
    • Set up disaster recovery with an RPO of 15 minutes and RTO of 1 hour.
    • Ensure PCI-DSS compliance for payment processing.

    Constraints:

    • The migration must be completed in 4 months (before the code freeze).
    • The Oracle database license cannot be easily transferred to the cloud.
    • The team has no experience with Kubernetes or containers yet.

    QUESTION:
    Given the 4-month timeline and the CTO's constraints, which migration strategy should you recommend for the VMware environment?

    View full case study page →

    GCP PCA · Question 08 · Compliance Design

    CASE STUDY: ShopGlobal

    Company Overview:
    ShopGlobal is an international e-commerce retailer. They are preparing for their largest annual sales event (Black Friday) and want to migrate off their aging on-premises infrastructure.

    Current Technical Environment:

    • 3 on-premises data centers (US-East, US-West, EU-Central).
    • VMware vSphere environment with 500 VMs.
    • Monolithic Java application running on Tomcat.
    • Oracle RAC database for transactions.
    • 50 TB of product images on SAN storage.

    Business Requirements:

    • Ensure 100% availability during the upcoming holiday season.
    • Modernize the application architecture over the next 3 years.
    • Reduce capital expenditure (CapEx) by shifting to an OpEx model.

    Executive Statements:

    • CEO: "Downtime during Black Friday costs us $1M per hour. We need bulletproof reliability."
    • CFO: "We want to stop buying hardware. Move everything to a pay-as-you-go model."
    • CTO: "We want to eventually move to microservices, but we don't have time to rewrite the app before the holidays."

    Technical Requirements:

    • Migrate the existing VMs to the cloud with minimal changes initially.
    • Implement a global CDN for product images to reduce latency.
    • Set up disaster recovery with an RPO of 15 minutes and RTO of 1 hour.
    • Ensure PCI-DSS compliance for payment processing.

    Constraints:

    • The migration must be completed in 4 months (before the code freeze).
    • The Oracle database license cannot be easily transferred to the cloud.
    • The team has no experience with Kubernetes or containers yet.

    QUESTION:
    To ensure PCI-DSS compliance for payment processing in the new cloud environment, which combination of GCP security controls should you implement?

    Answer options:

    A.

    Encrypt all data at rest using Google-managed encryption keys (GMEK) and disable external IP addresses on all VMs.

    B.

    Implement VPC Service Controls to create a secure perimeter, use Cloud DLP to tokenize credit card data, and enable Cloud Audit Logs.

    C.

    Deploy a third-party Next-Generation Firewall (NGFW) from the Google Cloud Marketplace and route all traffic through it.

    D.

    Store all payment data in a separate GCP project and use VPC Network Peering to connect it to the web servers.

    How to approach this question

    Look for the comprehensive security answer that addresses network isolation (VPC SC), data protection (DLP), and auditing (Audit Logs).

    Full Answer

    B.Implement VPC Service Controls to create a secure perimeter, use Cloud DLP to tokenize credit card data, and enable Cloud Audit Logs.✓ Correct
    Implement VPC Service Controls to create a secure perimeter, use Cloud DLP to tokenize credit card data, and enable Cloud Audit Logs.
    VPC Service Controls mitigates data exfiltration risks by creating a security perimeter around GCP resources. Cloud Data Loss Prevention (DLP) can tokenize sensitive PAN (Primary Account Number) data so it isn't stored in plaintext. Cloud Audit Logs provide the immutable tracking required by PCI-DSS Requirement 10.

    Common mistakes

    Assuming default encryption (Option A) is sufficient for PCI-DSS. Compliance requires explicit architectural controls for isolation and auditing.
    Question 07All questionsQuestion 09

    Practice the full GCP Professional Cloud Architect Practice Exam 7

    50 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01CASE STUDY: TechStream Gaming Company Overview: TechStream Gaming is a global multiplayer game d...HardQ02CASE STUDY: TechStream Gaming Company Overview: TechStream Gaming is a global multiplayer game d...MediumQ03CASE STUDY: TechStream Gaming Company Overview: TechStream Gaming is a global multiplayer game d...MediumQ04CASE STUDY: TechStream Gaming Company Overview: TechStream Gaming is a global multiplayer game d...MediumQ05CASE STUDY: TechStream Gaming Company Overview: TechStream Gaming is a global multiplayer game d...Medium
    View all 50 questions →