Google Certified Professional - Cloud Architect (GCP) Professional-Cloud-Architect Question # 38 Topic 4 Discussion

Google Certified Professional - Cloud Architect (GCP) Professional-Cloud-Architect Question # 38 Topic 4 Discussion

Professional-Cloud-Architect Exam Topic 4 Question 38 Discussion:
Question #: 38
Topic #: 4

For this question, refer to the Helicopter Racing League (HRL) case study. Your team is in charge of creating a

payment card data vault for card numbers used to bill tens of thousands of viewers, merchandise consumers,

and season ticket holders. You need to implement a custom card tokenization service that meets the following

requirements:

• It must provide low latency at minimal cost.

• It must be able to identify duplicate credit cards and must not store plaintext card numbers.

• It should support annual key rotation.

Which storage approach should you adopt for your tokenization service?


A.

Store the card data in Secret Manager after running a query to identify duplicates.


B.

Encrypt the card data with a deterministic algorithm stored in Firestore using Datastore mode.


C.

Encrypt the card data with a deterministic algorithm and shard it across multiple Memorystore instances.


D.

Use column-level encryption to store the data in Cloud SQL.


Get Premium Professional-Cloud-Architect Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.