Detect Non-EU Healthcare Data Storage Violations | PCSE
Your EU-based organization stores both Personally Identifiable Information (PII) and non-PII data in Cloud Storage buckets across multiple Google Cloud regions. EU data privacy laws require that the PII data must not be stored outside of the EU. To help meet this compliance requirement, you want to detect if Cloud Storage buckets outside of the EU contain healthcare data. What should you do?
Community Votes
80% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests knowledge of detective versus preventive controls in Google Cloud, specifically how SCC Premium automates compliance monitoring against regional data residency regulations.
This page explains why Security Command Center Premium’s compliance monitoring is the correct solution for detecting regulatory violations like storing healthcare data outside the EU. It clarifies why sensitive data scanning and log sinks fall short for continuous compliance detection.
Many candidates choose Sensitive Data Protection jobs, mistakenly believing batch scanning fulfills continuous compliance detection requirements instead of using built-in regulatory frameworks.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Security Command Center Premium provides out-of-the-box compliance monitoring that automatically evaluates cloud resources against recognized standards like GDPR and healthcare regulations. When enabled, it continuously scans storage buckets and flags any that violate data residency rules, such as hosting protected health information outside the EU. This aligns perfectly with the requirement to detect, not just prevent, cross-border data placement.Why the Other Options Are Wrong
Option A uses Sensitive Data Protection, which performs point-in-time classification rather than continuous compliance tracking and lacks native geographic enforcement checks. Option B filters logs by location but cannot inspect bucket contents to identify healthcare data. Option D relies on an Organization Policy constraint, which is a preventive control that blocks new deployments but does not retroactively detect or alert on already-existing non-compliant buckets.Community Comment Notes
Several learners initially favored the data scanning approach, arguing that specifying an infoType would locate the relevant files. However, experienced engineers pointed out that continuous regulatory tracking requires SCC’s compliance framework, noting that clicking into the appropriate standard automatically surfaces location-based violations. One commenter emphasized that "prevention constraints do not satisfy detective monitoring requirements," confirming the necessity of active compliance dashboards over manual scans.Official Reference
Exam Strategy
Focus on distinguishing between preventive controls like Organization Policies and detective controls like Security Command Center when exam questions explicitly ask you to detect or monitor compliance violations. Always match the action verb to the correct security service capability.
Frequently Asked Questions
Why is Sensitive Data Protection not the best choice here?
SDP performs point-in-time classification scans rather than continuous compliance tracking, making it unsuitable for ongoing regulatory detection.
Can Organization Policies detect existing non-compliant buckets?
No, Organization Policies act as preventive controls that block new resource creation but do not audit or alert on already deployed infrastructure.