Nordhavn Insurance must not store or process policy data outside the European Union and enforces the resource locations policy accordingly. A product team needs a relational database with zero data loss if a region is lost and strongly consistent global reads, and has proposed a Spanner instance in a North American multi-region configuration. What should you do?
- A.
Deploy a regional Spanner instance in europe-west4 and copy backups to a United States bucket.
- B.
Create the Spanner instance in an EU multi-region configuration, with its Cloud KMS keys in that configuration's EU regions.
- C.
Request an exception relaxing the resource locations constraint, then deploy the North American multi-region instance as originally designed.
- D.
Deploy the North American instance but encrypt policy data in the application with an EU key.
Show answer
Answer: B
The organization policy and the residency rule are hard boundaries, so the design must use a multi-region configuration whose replicas all sit in allowed EU regions.
- A. A regional instance cannot survive the loss of its region without data loss, and copying backups to the United States violates residency.
- B. An EU multi-region configuration with keys in the replica regions satisfies residency and the organization policy while still delivering zero data loss and strong consistency.
- C. Relaxing the guardrail to fit a design breaks the supervisory rule the policy implements and would fail audit, regardless of technical feasibility.
- D. Storing ciphertext outside the EU is still storing the data outside the EU, so application-level encryption does not satisfy a residency requirement.
