Detect Non-EU Healthcare Data Storage Violations | PCSE

Compliance Monitoring & Security Command Center
Answer Correct answer: C — Enable Security Command Center Premium compliance monitoring to detect storage buckets containing healthcare data outside the EU.

Your EU-based organization stores both Personally Identifiable Information (PII) and non-PII data in Cloud Storage buckets across multiple Google Cloud regions. EU data privacy laws require that the PII data must not be stored outside of the EU. To help meet this compliance requirement, you want to detect if Cloud Storage buckets outside of the EU contain healthcare data. What should you do?

  1. Create a Sensitive Data Protection job. Specify the infoType of data to be detected and run the job across all Google Cloud Storage buckets.
  2. Create a log sink with a filter on resourceLocation.currentLocations. Trigger an alert if a log message appears with a non- EUcountry.
  3. Activate Security Command Center Premium. Use compliance monitoring to detect resources that do not follow the applicable healthcare regulation. Correct Answer
  4. Enforce the gcp.resourceLocations organization policy and add "EU" in a custom rule that only applies on resources with the tag "healthcare".

Community Votes

A
80%
C
20%

80% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests knowledge of detective versus preventive controls in Google Cloud, specifically how SCC Premium automates compliance monitoring against regional data residency regulations.

This page explains why Security Command Center Premium’s compliance monitoring is the correct solution for detecting regulatory violations like storing healthcare data outside the EU. It clarifies why sensitive data scanning and log sinks fall short for continuous compliance detection.

Many candidates choose Sensitive Data Protection jobs, mistakenly believing batch scanning fulfills continuous compliance detection requirements instead of using built-in regulatory frameworks.

Community Discussion (3 comments)

LegoJesus 👍 1 Selected: C
Answer should be C. A - a data protection job just finds data that might contain PII. If you run it on all buckets in all regions, that won't confirm with the requirements of detecting buckets outside the EU. B - Irrelevant. C - Compliance monitoring in SCC will do this job for you. Just go in, click the compliance you're interested in (e.g. GDPR, healthcare data etc), and it will tell you why you're not compliant and where. D - Irrelevant.
MoAk 👍 1 Selected: A
Definitely A
BondleB 👍 1 Selected: A
Specifying the info Type of data to be detected allows to find storage buckets outside the EU that contain healthcare data.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Security Command Center Premium provides out-of-the-box compliance monitoring that automatically evaluates cloud resources against recognized standards like GDPR and healthcare regulations. When enabled, it continuously scans storage buckets and flags any that violate data residency rules, such as hosting protected health information outside the EU. This aligns perfectly with the requirement to detect, not just prevent, cross-border data placement.

Why the Other Options Are Wrong

Option A uses Sensitive Data Protection, which performs point-in-time classification rather than continuous compliance tracking and lacks native geographic enforcement checks. Option B filters logs by location but cannot inspect bucket contents to identify healthcare data. Option D relies on an Organization Policy constraint, which is a preventive control that blocks new deployments but does not retroactively detect or alert on already-existing non-compliant buckets.

Community Comment Notes

Several learners initially favored the data scanning approach, arguing that specifying an infoType would locate the relevant files. However, experienced engineers pointed out that continuous regulatory tracking requires SCC’s compliance framework, noting that clicking into the appropriate standard automatically surfaces location-based violations. One commenter emphasized that "prevention constraints do not satisfy detective monitoring requirements," confirming the necessity of active compliance dashboards over manual scans.

Official Reference

Exam Strategy

Focus on distinguishing between preventive controls like Organization Policies and detective controls like Security Command Center when exam questions explicitly ask you to detect or monitor compliance violations. Always match the action verb to the correct security service capability.

Frequently Asked Questions

Why is Sensitive Data Protection not the best choice here?

SDP performs point-in-time classification scans rather than continuous compliance tracking, making it unsuitable for ongoing regulatory detection.

Can Organization Policies detect existing non-compliant buckets?

No, Organization Policies act as preventive controls that block new resource creation but do not audit or alert on already deployed infrastructure.

Related Analysis

← Back to PCSE Study Guide