PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #79
You want to evaluate GCP for PCI compliance. You need to identify Google's inherent controls. Which document should you review to find the information?
The correct answer is A. Google Cloud Platform: Customer Responsibility Matrix. The Google Cloud Platform Customer Responsibility Matrix explicitly documents the division of compliance responsibilities between Google (inherent/built-in controls) and the customer (customer-managed controls). This is the authoritative source for understanding what PCI DSS…
Question
Options
- AGoogle Cloud Platform: Customer Responsibility Matrix
- BPCI DSS Requirements and Security Assessment Procedures
- CPCI SSC Cloud Computing Guidelines
- DProduct documentation for Compute Engine
How the community answered
(48 responses)- A92% (44)
- B2% (1)
- C2% (1)
- D4% (2)
Explanation
The Google Cloud Platform Customer Responsibility Matrix explicitly documents the division of compliance responsibilities between Google (inherent/built-in controls) and the customer (customer-managed controls). This is the authoritative source for understanding what PCI DSS controls Google handles by default on GCP. Option B (PCI DSS Requirements and Security Assessment Procedures) is the standard itself - it defines what must be done, not who does it on GCP. Option C (PCI SSC Cloud Computing Guidelines) is general industry guidance for cloud environments, not GCP-specific. Option D (Compute Engine product documentation) covers technical capabilities, not compliance control ownership.
Topics
Community Discussion
No community discussion yet for this question.