nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #108

You are responsible for implementing a payment processing environment that will use Kubernetes and need to apply proper security controls. What should you do?

The correct answer is D. Is correct because this is a requirement of PCI DSS in Sections 5 and 11. For a payment processing environment using Kubernetes, proper security controls must be applied because they are a fundamental requirement of the Payment Card Industry Data Security Standard (PCI DSS), specifically referencing Sections 5 and 11.

Submitted by yousef_jo· Apr 18, 2026Ensuring compliance

Question

You are responsible for implementing a payment processing environment that will use Kubernetes and need to apply proper security controls. What should you do?

Options

  • AIs not correct because this solution is not specific to Kubernetes.
  • BIs not correct because this would render the environment non-functional.
  • CIs not correct because this solution is not specific to Kubernetes.
  • DIs correct because this is a requirement of PCI DSS in Sections 5 and 11.

How the community answered

(36 responses)
  • A
    14% (5)
  • B
    6% (2)
  • C
    3% (1)
  • D
    78% (28)

Why each option

For a payment processing environment using Kubernetes, proper security controls must be applied because they are a fundamental requirement of the Payment Card Industry Data Security Standard (PCI DSS), specifically referencing Sections 5 and 11.

AIs not correct because this solution is not specific to Kubernetes.

This choice provides a generic reason ('not specific to Kubernetes') without stating what the solution is, making it an unhelpful and incomplete justification.

BIs not correct because this would render the environment non-functional.

This choice states the action would render the environment non-functional, which is an undesirable outcome and not a valid security control to implement.

CIs not correct because this solution is not specific to Kubernetes.

Similar to A, this choice provides a generic reason ('not specific to Kubernetes') without stating what the solution is, making it an unhelpful and incomplete justification.

DIs correct because this is a requirement of PCI DSS in Sections 5 and 11.Correct

For a payment processing environment using Kubernetes, implementing robust security controls is essential due to regulatory compliance, specifically the Payment Card Industry Data Security Standard (PCI DSS), which mandates requirements such as those found in Sections 5 (malware protection) and 11 (regular security testing).

Concept tested: PCI DSS compliance for payment processing in Kubernetes

Source: https://cloud.google.com/security/compliance/pci-dss

Topics

#PCI DSS#Compliance#Kubernetes Security#Payment Processing

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice