Google PCA: Security, Compliance and Data Protection Architecture — Study Guide

Part of the Google Professional Cloud Architect — Study Guide. Practice with verified answers in the Google exam hub, or take timed practice tests on ExamRoll.io.

Overview

Security, compliance, and data protection in Google Cloud are built on shared responsibility and defense in depth. Google secures the underlying infrastructure, while you architect secure identities, networks, applications, and data handling. Adopt Zero Trust as a guiding model: never implicitly trust the network, continuously verify identity and context, and strictly enforce least privilege. Design for compromise: assume credentials can leak, endpoints can be probed, and internal services can be misused. Compensate with multiple controls (preventive, detective, responsive), strong cryptography and key management, robust monitoring, and practiced incident response.

Trade-offs are inevitable. Stronger controls can increase latency, operational complexity, and costs. Your architecture should explicitly weigh risks against usability and performance while preserving provable compliance and forensics readiness.

Identity and Access Architecture

Example (impersonation without creating keys):

Data Protection and Cryptography

Example (CMEK with rotation):

Example (add new secret version):

Network and Edge Security

Security Operations, Monitoring, and Compliance

Practical Problem Scenario

NimbusPay, a fintech SaaS, must process PCI-tagged data across multi-tenant microservices on Google Cloud, enforce data residency in the EU, protect against API-layer attacks, and produce auditable evidence of controls. They will roll out a new v2 API while keeping v1 live under the same hostname.

Approach:

  1. Partition projects and identities
  1. Enforce Zero Trust and least privilege
  1. Remove static service account keys
  1. Protect data with CMEK and regional controls
  1. Adopt application-layer encryption for card data
  1. Centralize secrets and rotate automatically
  1. Segment networks and control egress
  1. Wrap data services with VPC Service Controls
  1. Secure the edge and APIs
  1. Harden compute and attest artifacts
  1. Monitor posture and threats with SCC
  1. Log, retain, and produce evidence
  1. Prepare incident response and forensics

Short commands that support the rollout:

With these steps, NimbusPay achieves layered protection (identity, crypto, network, and edge), verifiable compliance, controlled API evolution under one hostname, and readiness to detect, contain, and recover from incidents.


Networking · All domains · Reliability

Practice these questions → · Timed practice on ExamRoll.io →

Pass the whole exam — not just this question

You found this answer. Get every verified question and explanation in one place, and save hours of prep. Free to start.

Pass your exam →

Browse Google →

Related guides

All-in-one access

One subscription. Every exam.

Every plan unlocks unlimited answer search, practice tests, AI explanations, and the full resource library — in 20+ languages.

Monthly
24.87
Just €0.83/day
Everything included:
  • Unlimited answer search
  • Unlimited practice tests
  • AI-powered explanations
  • Full resource library
  • 20+ languages
  • Weekly content updates
  • Rewards & referrals
  • Priority support
Start free trial

No credit card required*

Best value
12 months
179.87
Just €0.49/daySave 40%
Everything included:
  • Unlimited answer search
  • Unlimited practice tests
  • AI-powered explanations
  • Full resource library
  • 20+ languages
  • Weekly content updates
  • Rewards & referrals
  • Priority support
Start free trial

No credit card required*

✓ Free plan included · ✓ Cancel anytime · ✓ All plans unlock the full product