GCP Regulatory Compliance & Legal Framework 3 — Questions and Answers
Question 1: An organization subject to FedRAMP requirements wants to host a government application on GCP. What must GCP demonstrate to be eligible?
- ISO 27001 certification
- SOC 1 Type I attestation
- FedRAMP Authorization (Correct answer)
- NIST SP 800-53 self-assessment
Correct answer: FedRAMP Authorization
FedRAMP Authorization is the mandatory compliance program that cloud service providers must achieve before U.S. federal agencies can use their services.
Question 2: Under the Gramm-Leach-Bliley Act (GLBA), financial institutions must provide customers with a privacy notice describing their data-sharing practices. This is known as the:
- Opt-in disclosure
- Annual privacy notice (Correct answer)
- Financial data statement
- Consumer protection report
Correct answer: Annual privacy notice
The GLBA Safeguards Rule requires financial institutions to send customers an annual privacy notice explaining what information is collected and how it is shared.
Question 3: Which GCP compliance offering specifically addresses requirements for U.S. Department of Defense workloads at Impact Levels 2 and 4?
- FedRAMP High
- DoD IL Authorization (Correct answer)
- ITAR compliance
- CJIS compliance
Correct answer: DoD IL Authorization
GCP holds DoD Impact Level authorizations (IL2, IL4, IL5) for workloads that meet Department of Defense cloud security requirements at varying sensitivity levels.
Question 4: A GDPR Data Protection Impact Assessment (DPIA) is mandatory when processing is likely to result in:
- Any use of third-party processors
- A high risk to the rights and freedoms of individuals (Correct answer)
- Storage of data outside the EU
- Encryption of personal data
Correct answer: A high risk to the rights and freedoms of individuals
Under GDPR Article 35, a DPIA is required when processing operations are likely to result in a high risk to the rights and freedoms of natural persons.
Question 5: The California Consumer Privacy Act (CCPA) grants California residents the right to know what personal information is collected and the right to:
- Correct inaccurate data only
- Request deletion and opt out of its sale (Correct answer)
- Receive monetary compensation for any data use
- Restrict all third-party data processing
Correct answer: Request deletion and opt out of its sale
CCPA gives consumers the right to know, the right to delete, and the right to opt out of the sale of their personal information to third parties.
Question 6: When Google Cloud acts as a data processor under GDPR, what document formalizes the legal relationship with the customer as data controller?
- Service Level Agreement (SLA)
- Data Processing Agreement (DPA) (Correct answer)
- Acceptable Use Policy (AUP)
- Cloud Framework Contract (CFC)
Correct answer: Data Processing Agreement (DPA)
A Data Processing Agreement (DPA) is legally required under GDPR Article 28 to govern the relationship between a data controller and a data processor.
Question 7: Which GCP tool allows organizations to define and enforce policies that restrict what resources can be created, ensuring compliance with internal governance rules?
- Cloud IAM
- VPC Service Controls
- Organization Policy Service (Correct answer)
- Security Command Center
Correct answer: Organization Policy Service
The Organization Policy Service allows administrators to set constraints on GCP resources across the entire organization, folder, or project hierarchy.
An organization subject to FedRAMP requirements wants to host a government application on GCP.
What must GCP demonstrate to be eligible?