GCP Professional Standards & Ethics 2 — Questions and Answers
Question 1: Under GDPR, what is the maximum fine for the most serious violations?
- 2% of annual global turnover or €10 million
- 4% of annual global turnover or €20 million (Correct answer)
- 1% of annual global turnover or €5 million
- 5% of annual global turnover or €25 million
Correct answer: 4% of annual global turnover or €20 million
GDPR's highest tier penalty is 4% of annual global turnover or €20 million, whichever is greater.
Question 2: Which GCP service is specifically designed to help organizations meet HIPAA compliance for health data workloads?
- Cloud Spanner with default settings
- Cloud Healthcare API with a signed Business Associate Agreement (Correct answer)
- BigQuery without additional configuration
- Cloud Functions without encryption
Correct answer: Cloud Healthcare API with a signed Business Associate Agreement
Cloud Healthcare API supports HIPAA workloads when paired with a signed BAA from Google.
Question 3: What does the principle of data minimization require?
- Storing all collected data indefinitely for future analytics
- Collecting only the data necessary for the specified, legitimate purpose (Correct answer)
- Encrypting all data at rest and in transit
- Replicating data across multiple geographic regions
Correct answer: Collecting only the data necessary for the specified, legitimate purpose
Data minimization means limiting personal data collection to what is strictly necessary for the stated purpose.
Question 4: A cloud professional discovers customer PII is stored in unencrypted application logs. What should they do first?
- Delete the logs immediately without documentation
- Ignore it if no external breach has occurred yet
- Report it through proper incident response channels and preserve evidence (Correct answer)
- Wait until the next scheduled security audit to address it
Correct answer: Report it through proper incident response channels and preserve evidence
Discovered PII exposure must be escalated through incident response procedures immediately, not ignored or unilaterally deleted.
Question 5: What does the GDPR 'right to erasure' (right to be forgotten) require of data processors?
- Deleting only live database copies, retaining backups
- Erasing an individual's personal data upon valid request when legal conditions are met (Correct answer)
- Retaining data for seven years before any deletion is permitted
- Anonymizing data rather than permanently deleting it
Correct answer: Erasing an individual's personal data upon valid request when legal conditions are met
The right to erasure obligates processors to delete personal data when the individual requests it and no overriding legal basis exists.
Question 6: Which compliance framework is specifically designed to govern the security of payment card data?
- HIPAA
- SOC 2 Type II
- PCI DSS (Correct answer)
- FedRAMP
Correct answer: PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) specifically governs the handling and security of cardholder data.
Question 7: What is the primary purpose of a Data Processing Agreement (DPA) between a cloud customer and a cloud provider?
- To define cloud resource pricing and billing terms
- To legally govern how the processor handles personal data on behalf of the controller (Correct answer)
- To establish SLA performance benchmarks for database operations
- To specify technical data formats for interoperability
Correct answer: To legally govern how the processor handles personal data on behalf of the controller
A DPA is a legally binding contract that defines the processor's obligations and restrictions when handling the controller's personal data.
Under GDPR, what is the maximum fine for the most serious violations?