← All GCP Flashcard Decks

Professional Standards & Ethics Flashcards

7 cards from real GCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Professional Standards & Ethics flashcards as text
  1. Under GDPR, what is the maximum fine for the most serious violations?

    Answer: 4% of annual global turnover or €20 million

    GDPR's highest tier penalty is 4% of annual global turnover or €20 million, whichever is greater.

  2. Which GCP service is specifically designed to help organizations meet HIPAA compliance for health data workloads?

    Answer: Cloud Healthcare API with a signed Business Associate Agreement

    Cloud Healthcare API supports HIPAA workloads when paired with a signed BAA from Google.

  3. What does the principle of data minimization require?

    Answer: Collecting only the data necessary for the specified, legitimate purpose

    Data minimization means limiting personal data collection to what is strictly necessary for the stated purpose.

  4. A cloud professional discovers customer PII is stored in unencrypted application logs. What should they do first?

    Answer: Report it through proper incident response channels and preserve evidence

    Discovered PII exposure must be escalated through incident response procedures immediately, not ignored or unilaterally deleted.

  5. What does the GDPR 'right to erasure' (right to be forgotten) require of data processors?

    Answer: Erasing an individual's personal data upon valid request when legal conditions are met

    The right to erasure obligates processors to delete personal data when the individual requests it and no overriding legal basis exists.

  6. Which compliance framework is specifically designed to govern the security of payment card data?

    Answer: PCI DSS

    PCI DSS (Payment Card Industry Data Security Standard) specifically governs the handling and security of cardholder data.

  7. What is the primary purpose of a Data Processing Agreement (DPA) between a cloud customer and a cloud provider?

    Answer: To legally govern how the processor handles personal data on behalf of the controller

    A DPA is a legally binding contract that defines the processor's obligations and restrictions when handling the controller's personal data.