ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 21 - Professional Cloud Security Engineer discussion

Report
Export

In order to meet PCI DSS requirements, a customer wants to ensure that all outbound traffic is authorized.

Which two cloud offerings meet this requirement without additional compensating controls? (Choose two.)

A.
App Engine
Answers
A.
App Engine
B.
Cloud Functions
Answers
B.
Cloud Functions
C.
Compute Engine
Answers
C.
Compute Engine
D.
Google Kubernetes Engine
Answers
D.
Google Kubernetes Engine
E.
Cloud Storage
Answers
E.
Cloud Storage
Suggested answer: C, D

Explanation:

App Engine ingress firewall rules are available, but egress rules are not currently available. Per requirements 1.2.1 and 1.3.4, you must ensure that all outbound traffic is authorized. SAQ A-EP and SAQ D--type merchants must provide compensating controls or use a different Google Cloud product. Compute Engine and GKE are the preferred alternatives. https://cloud.google.com/solutions/pci-dss-compliance-in-gcp

asked 18/09/2024
Leandra Felipe
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first