nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #79

You want to evaluate GCP for PCI compliance. You need to identify Google's inherent controls. Which document should you review to find the information?

The correct answer is A. Google Cloud Platform: Customer Responsibility Matrix. The Google Cloud Platform Customer Responsibility Matrix explicitly documents the division of compliance responsibilities between Google (inherent/built-in controls) and the customer (customer-managed controls). This is the authoritative source for understanding what PCI DSS…

Submitted by hassan_iq· Apr 18, 2026Ensuring compliance

Question

You want to evaluate GCP for PCI compliance. You need to identify Google's inherent controls. Which document should you review to find the information?

Options

  • AGoogle Cloud Platform: Customer Responsibility Matrix
  • BPCI DSS Requirements and Security Assessment Procedures
  • CPCI SSC Cloud Computing Guidelines
  • DProduct documentation for Compute Engine

How the community answered

(48 responses)
  • A
    92% (44)
  • B
    2% (1)
  • C
    2% (1)
  • D
    4% (2)

Explanation

The Google Cloud Platform Customer Responsibility Matrix explicitly documents the division of compliance responsibilities between Google (inherent/built-in controls) and the customer (customer-managed controls). This is the authoritative source for understanding what PCI DSS controls Google handles by default on GCP. Option B (PCI DSS Requirements and Security Assessment Procedures) is the standard itself - it defines what must be done, not who does it on GCP. Option C (PCI SSC Cloud Computing Guidelines) is general industry guidance for cloud environments, not GCP-specific. Option D (Compute Engine product documentation) covers technical capabilities, not compliance control ownership.

Topics

#PCI DSS#Compliance documentation#Shared responsibility model#Google Cloud controls

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice