Securing Sensitive Patient Data with Assured Workloads

Cloud Security Compliance
Answer Correct answer: B — Deploy Assured Workloads in an approved region, configure Access Approval for administrative actions, and enable Cloud Audit Logs with Access Transparency.

You work for a healthcare provider that is expanding into the cloud to store and process sensitive patient data. You must ensure the chosen Google Cloud configuration meets these strict regulatory requirements: • Data must reside within specific geographic regions. • Certain administrative actions on patient data require explicit approval from designated compliance officers. • Access to patient data must be auditable. What should you do?

  1. Select a standard Google Cloud region. Restrict access to patient data based on user location and job function by using Access Context Manager. Enable both Cloud Audit Logging and Access Transparency.
  2. Deploy an Assured Workloads environment in an approved region. Configure Access Approval for sensitive operations on patient data. Enable both Cloud Audit Logs and Access Transparency. Correct Answer
  3. Deploy an Assured Workloads environment in multiple regions for redundancy. Utilize custom IAM roles with granular permissions. Isolate network-level data by using VPC Service Controls.
  4. Select multiple standard Google Cloud regions for high availability. Implement Access Control Lists (ACLs) on individual storage objects containing patient data. Enable Cloud Audit Logs.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests Google Cloud compliance services for regulated industries, with the trap being generic IAM or VPC controls that lack mandated approval workflows and certified data residency boundaries.

Assured Workloads combined with Access Approval and Cloud Audit Logs provides a compliant foundation for healthcare data residency and governance in Google Cloud. This page confirms why Option B satisfies all strict regulatory mandates.

Option A is frequently chosen because Access Context Manager handles location-based restrictions, but it lacks the explicit administrative approval workflow and certified workload isolation required for healthcare compliance.

Community Discussion (3 comments)

Pime13 👍 1 Selected: B
https://cloud.google.com/assured-workloads/docs/overview
BondleB 👍 2 Selected: B
Option B fulfils the given strict regulatory requirements below: • Data must reside within specific geographic regions. • Certain administrative actions on patient data require explicit approval from designated compliance officers. • Access to patient data must be auditable.
yokoyan 👍 2 Selected: B
I think it's B.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Assured Workloads guarantees data residency in pre-approved regions, directly satisfying the geographic constraint. Access Approval enforces a mandatory explicit approval step before any administrative changes occur, meeting the compliance officer requirement. Pairing these with Cloud Audit Logs and Access Transparency ensures full visibility and auditability of both user and Google-level access, fulfilling the auditing mandate.

Why the Other Options Are Wrong

Option A relies on standard regions and Access Context Manager, which restricts access by location but cannot enforce explicit approval workflows or provide the certified compliance posture needed for health data. Option C emphasizes network isolation via VPC Service Controls and custom IAM, but omits the required administrative approval mechanism and misplaces focus on redundancy over regulatory compliance. Option D uses basic ACLs and standard regions, lacking the centralized governance, explicit approval gates, and comprehensive audit trails demanded by healthcare regulations.

Community Comment Notes

Community members consistently validate Option B as the only configuration that maps directly to the three stated regulatory constraints. As BondleB noted, the combination of Assured Workloads, Access Approval, and audit features precisely fulfills the geographic, approval, and auditing requirements. Pime13 reinforced this by pointing to the official Assured Workloads documentation, confirming its suitability for regulated environments like healthcare.

Official Reference

Exam Strategy

When encountering regulated industry scenarios, immediately map phrases like “specific geographic regions” to Assured Workloads and “explicit approval” to Access Approval. Avoid generic security controls unless they explicitly satisfy compliance mandates like auditability and mandated approval workflows.

Frequently Asked Questions

Why not use Access Context Manager for geographic data restrictions?

Access Context Manager controls access by location but does not enforce certified data residency boundaries or explicit administrative approval workflows required for healthcare compliance.

Does Access Transparency replace Cloud Audit Logs?

No. Access Transparency logs Google’s access to your data, while Cloud Audit Logs track user and system activities; both are needed for complete regulatory auditability.

Related Analysis

← Back to PCSE Study Guide