Examtopics

Professional Cloud Security Engineer
  • Topic 1 Question 252

    Your organization is migrating a sensitive data processing workflow from on-premises infrastructure to Google Cloud. This workflow involves the collection, storage, and analysis of customer information that includes personally identifiable information (PII). You need to design security measures to mitigate the risk of data exfiltration in this new cloud environment. What should you do?

    • Encrypt all sensitive data in transit and at rest. Establish secure communication channels by using TLS and HTTPS protocols.

    • Implement a Cloud DLP solution to scan and identify sensitive information, and apply redaction or masking techniques to the PII. Integrate VPC SC with your network security controls to block potential data exfiltration attempts.

    • Restrict all outbound network traffic from cloud resources. Implement rigorous access controls and logging for all sensitive data and the systems that process the data.

    • Rely on employee expertise to prevent accidental data exfiltration incidents.


    シャッフルモード