CASE STUDY: HealthSecure
Company Overview:
HealthSecure provides electronic health record (EHR) systems and telemedicine platforms to hospitals across North America. They handle highly sensitive patient data.
Current Technical Environment:
Business Requirements:
Executive Statements:
Technical Requirements:
Constraints:
QUESTION:
To meet the CRO's requirement for strict network isolation and prevent data exfiltration of sensitive patient records, which GCP security feature must be implemented?
GCP PCA · Question 18 · Compliance Design
CASE STUDY: HealthSecure
Company Overview:
HealthSecure provides electronic health record (EHR) systems and telemedicine platforms to hospitals across North America. They handle highly sensitive patient data.
Current Technical Environment:
Business Requirements:
Executive Statements:
Technical Requirements:
Constraints:
QUESTION:
To meet the requirement for comprehensive audit logging of all data access for third-party auditors, what must you configure?
Answer options:
Admin Activity audit logs are enabled by default and provide sufficient detail for data access.
Enable Data Access audit logs for all relevant GCP services in Cloud Audit Logs.
Install the Ops Agent on all VMs to capture application logs and export them to BigQuery.
Use VPC Flow Logs to track all IP addresses accessing the database.
50 questions · hints · full answers · grading