
Ultimate access to all questions.
You are a security team member at an organization that uses a single GCP project. This project contains credit card payment processing systems, web applications, and data processing systems. Your goal is to reduce the number of systems that are subject to PCI DSS audit requirements. What should you do?
A
Use multi-factor authentication for admin access to the web application.
B
Use only applications certified compliant with PA-DSS.
C
Move the cardholder data environment into a separate GCP project.
D
Use VPN for all connections between your office and cloud environments.