Regulatory Compliance & Legal Framework Flashcards
7 cards from real GCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Regulatory Compliance & Legal Framework flashcards as text
An organization subject to FedRAMP requirements wants to host a government application on GCP. What must GCP demonstrate to be eligible?
Answer: FedRAMP Authorization
FedRAMP Authorization is the mandatory compliance program that cloud service providers must achieve before U.S. federal agencies can use their services.
Under the Gramm-Leach-Bliley Act (GLBA), financial institutions must provide customers with a privacy notice describing their data-sharing practices. This is known as the:
Answer: Annual privacy notice
The GLBA Safeguards Rule requires financial institutions to send customers an annual privacy notice explaining what information is collected and how it is shared.
Which GCP compliance offering specifically addresses requirements for U.S. Department of Defense workloads at Impact Levels 2 and 4?
Answer: DoD IL Authorization
GCP holds DoD Impact Level authorizations (IL2, IL4, IL5) for workloads that meet Department of Defense cloud security requirements at varying sensitivity levels.
A GDPR Data Protection Impact Assessment (DPIA) is mandatory when processing is likely to result in:
Answer: A high risk to the rights and freedoms of individuals
Under GDPR Article 35, a DPIA is required when processing operations are likely to result in a high risk to the rights and freedoms of natural persons.
The California Consumer Privacy Act (CCPA) grants California residents the right to know what personal information is collected and the right to:
Answer: Request deletion and opt out of its sale
CCPA gives consumers the right to know, the right to delete, and the right to opt out of the sale of their personal information to third parties.
When Google Cloud acts as a data processor under GDPR, what document formalizes the legal relationship with the customer as data controller?
Answer: Data Processing Agreement (DPA)
A Data Processing Agreement (DPA) is legally required under GDPR Article 28 to govern the relationship between a data controller and a data processor.
Which GCP tool allows organizations to define and enforce policies that restrict what resources can be created, ensuring compliance with internal governance rules?
Answer: Organization Policy Service
The Organization Policy Service allows administrators to set constraints on GCP resources across the entire organization, folder, or project hierarchy.