CASE STUDY: HealthSecure
Company Overview:
HealthSecure provides electronic health record (EHR) systems and telemedicine platforms to hospitals across North America. They handle highly sensitive patient data.
Current Technical Environment:
Business Requirements:
Executive Statements:
Technical Requirements:
Constraints:
QUESTION:
To meet the CRO's requirement for strict network isolation and prevent data exfiltration of sensitive patient records, which GCP security feature must be implemented?
GCP PCA · Question 17 · Design for Security
CASE STUDY: HealthSecure
Company Overview:
HealthSecure provides electronic health record (EHR) systems and telemedicine platforms to hospitals across North America. They handle highly sensitive patient data.
Current Technical Environment:
Business Requirements:
Executive Statements:
Technical Requirements:
Constraints:
QUESTION:
How should you implement the encryption requirement to satisfy the constraint of using Customer-Managed Encryption Keys (CMEK)?
Answer options:
Rely on Google's default encryption at rest, as it automatically rotates keys and is HIPAA compliant.
Generate keys in Cloud Key Management Service (KMS) and configure GCP services (like Cloud Storage and Compute Engine) to use these keys for encryption at rest.
Provide your own encryption keys in a text file stored in a secure Cloud Storage bucket and reference them in application code.
Use Customer-Supplied Encryption Keys (CSEK) by keeping the keys on-premises and sending them with every API request.
50 questions · hints · full answers · grading