Securing Sensitive Patient Data with Assured Workloads
You work for a healthcare provider that is expanding into the cloud to store and process sensitive patient data. You must ensure the chosen Google Cloud configuration meets these strict regulatory requirements: • Data must reside within specific geographic regions. • Certain administrative actions on patient data require explicit approval from designated compliance officers. • Access to patient data must be auditable. What should you do?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests Google Cloud compliance services for regulated industries, with the trap being generic IAM or VPC controls that lack mandated approval workflows and certified data residency boundaries.
Assured Workloads combined with Access Approval and Cloud Audit Logs provides a compliant foundation for healthcare data residency and governance in Google Cloud. This page confirms why Option B satisfies all strict regulatory mandates.
Option A is frequently chosen because Access Context Manager handles location-based restrictions, but it lacks the explicit administrative approval workflow and certified workload isolation required for healthcare compliance.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Assured Workloads guarantees data residency in pre-approved regions, directly satisfying the geographic constraint. Access Approval enforces a mandatory explicit approval step before any administrative changes occur, meeting the compliance officer requirement. Pairing these with Cloud Audit Logs and Access Transparency ensures full visibility and auditability of both user and Google-level access, fulfilling the auditing mandate.Why the Other Options Are Wrong
Option A relies on standard regions and Access Context Manager, which restricts access by location but cannot enforce explicit approval workflows or provide the certified compliance posture needed for health data. Option C emphasizes network isolation via VPC Service Controls and custom IAM, but omits the required administrative approval mechanism and misplaces focus on redundancy over regulatory compliance. Option D uses basic ACLs and standard regions, lacking the centralized governance, explicit approval gates, and comprehensive audit trails demanded by healthcare regulations.Community Comment Notes
Community members consistently validate Option B as the only configuration that maps directly to the three stated regulatory constraints. As BondleB noted, the combination of Assured Workloads, Access Approval, and audit features precisely fulfills the geographic, approval, and auditing requirements. Pime13 reinforced this by pointing to the official Assured Workloads documentation, confirming its suitability for regulated environments like healthcare.Official Reference
Exam Strategy
When encountering regulated industry scenarios, immediately map phrases like “specific geographic regions” to Assured Workloads and “explicit approval” to Access Approval. Avoid generic security controls unless they explicitly satisfy compliance mandates like auditability and mandated approval workflows.
Frequently Asked Questions
Why not use Access Context Manager for geographic data restrictions?
Access Context Manager controls access by location but does not enforce certified data residency boundaries or explicit administrative approval workflows required for healthcare compliance.
Does Access Transparency replace Cloud Audit Logs?
No. Access Transparency logs Google’s access to your data, while Cloud Audit Logs track user and system activities; both are needed for complete regulatory auditability.