GCP Regulatory Compliance & Legal Framework 5 — Questions and Answers
Question 1: A company operating in multiple states must comply with various U.S. state privacy laws. Which state law is considered the most influential model for other state privacy legislation?
- Virginia Consumer Data Protection Act (VCDPA)
- California Consumer Privacy Act (CCPA) and its CPRA amendment (Correct answer)
- Colorado Privacy Act (CPA)
- Texas Data Privacy and Security Act (TDPSA)
Correct answer: California Consumer Privacy Act (CCPA) and its CPRA amendment
The CCPA and its amendment, the CPRA, are the most influential U.S. state privacy laws, establishing many rights and obligations that other states have since modeled.
Question 2: Under SOC 2 compliance, which Trust Services Criteria category directly addresses whether a system's controls protect against unauthorized access?
- Availability
- Processing Integrity
- Confidentiality
- Security (Common Criteria) (Correct answer)
Correct answer: Security (Common Criteria)
The Security (Common Criteria) category is the only mandatory TSC category in SOC 2 and directly covers protection of systems against unauthorized access, use, or disclosure.
Question 3: Which GCP feature enables organizations to restrict data residency so that covered data is stored and processed only within specific geographic regions?
- Cloud Armor policies
- Organization Policy constraints (resource location restriction) (Correct answer)
- Cloud CDN edge caching
- VPC peering rules
Correct answer: Organization Policy constraints (resource location restriction)
Organization Policy constraints such as `gcp.resourceLocations` restrict where GCP resources can be created, helping organizations meet data residency and sovereignty requirements.
Question 4: Under GDPR, what is the legal term for transferring personal data from the EU to a country that the European Commission has deemed to have adequate privacy protections?
- Standard Contractual Clauses transfer
- Adequacy decision transfer (Correct answer)
- Binding Corporate Rules transfer
- Derogation-based transfer
Correct answer: Adequacy decision transfer
An adequacy decision issued by the European Commission means personal data can flow freely to that third country without additional safeguards.
Question 5: A GCP customer wants to validate that their cloud environment meets CIS Benchmark recommendations. Which GCP tool provides automated assessment against CIS Benchmarks?
- Cloud Trace
- Security Command Center (Security Health Analytics) (Correct answer)
- Cloud Profiler
- Cloud Deployment Manager
Correct answer: Security Command Center (Security Health Analytics)
Security Command Center's Security Health Analytics includes built-in detectors that assess GCP resources against CIS Benchmark controls and surface misconfigurations.
Question 6: Under HIPAA's Minimum Necessary Standard, covered entities accessing PHI must:
- Obtain written patient consent for every access
- Limit access and use to only what is required to accomplish the intended purpose (Correct answer)
- Encrypt all PHI regardless of access type
- Report every PHI access to HHS within 30 days
Correct answer: Limit access and use to only what is required to accomplish the intended purpose
The Minimum Necessary Standard requires that covered entities make reasonable efforts to limit PHI access to only what is necessary to accomplish the intended purpose.
Question 7: An organization must implement controls to comply with CJIS (Criminal Justice Information Services) Security Policy when accessing FBI criminal justice data in GCP. Which requirement is unique to CJIS compared to general cloud security standards?
- Requiring TLS 1.2 or higher for data in transit
- Mandatory background checks and security awareness training for personnel with access to CJI (Correct answer)
- Using multi-factor authentication for admin accounts
- Encrypting data at rest using AES-256
Correct answer: Mandatory background checks and security awareness training for personnel with access to CJI
CJIS uniquely requires that personnel with access to Criminal Justice Information (CJI) pass FBI-approved background checks and complete CJIS security awareness training.
A company operating in multiple states must comply with various U.S. state privacy laws.
Which state law is considered the most influential model for other state privacy legislation?