A global financial institution needs to build a highly secure and compliant data processing system on Google Cloud. The system will handle sensitive customer financial transactions, requiring strict data residency, encryption, and access control. Due to regulatory requirements, all data processing activities must be auditable, and data must be immediately available for analysis. The solution must also be cost-effective for petabyte-scale storage. Which combination of Google Cloud services should you recommend to meet these requirements?
- ACloud SQL for transactional data, App Engine for processing, and Security Command Center for compliance monitoring.
- BCloud Spanner for global transactions, Kubernetes Engine for processing, and Cloud DLP for data masking.
- CBigQuery for data warehousing, Dataflow for processing, Cloud Key Management Service (KMS) for encryption, Identity and Access Management (IAM) for access control, and Cloud Audit Logs for auditability.
- DCloud Storage with client-side encryption, Compute Engine for processing, and Cloud Logging for audit trails.
Show answer & explanationAnswer & explanation
Correct answer: C. BigQuery for data warehousing, Dataflow for processing, Cloud Key Management Service (KMS) for encryption, Identity and Access Management (IAM) for access control, and Cloud Audit Logs for auditability.
This scenario demands a comprehensive solution addressing data residency, encryption, access control, auditability, and petabyte-scale cost-effectiveness. BigQuery is ideal for petabyte-scale data warehousing and analytics. Dataflow provides scalable processing. KMS handles encryption keys, IAM manages granular access, and Cloud Audit Logs provide the necessary auditability for regulatory compliance. This combination directly addresses all specified requirements.
Why the other options are wrong
- A. Cloud SQL is not designed for petabyte-scale data warehousing. App Engine is for web applications, not large-scale data processing. Security Command Center is for security posture management, not primary audit logging.
- B. Cloud Spanner is for global transactional databases, not petabyte-scale analytical data warehousing. Kubernetes Engine requires significant operational overhead for data processing, and Cloud DLP is for data discovery and protection, not a primary audit log or encryption key management service.
- D. Client-side encryption is less robust for enterprise-wide compliance, Compute Engine is not optimized for petabyte-scale data processing without significant custom effort, and Cloud Logging alone may not meet all auditability requirements for financial regulations.
Secure & Compliant Data System
Designing data systems on Google Cloud that meet strict regulatory requirements for data residency, encryption, access control, auditability, and cost-effectiveness at scale.
- Uses BigQuery for petabyte-scale analytics.
- Leverages KMS for encryption key management.
- Implements IAM for granular access control.
- Relies on Cloud Audit Logs for comprehensive auditability.
Memory trick: Securely Analyze, Encrypt, Control, and Log all Financial Data for Compliance.