Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 178 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 178

Single answerGoogle Cloud Platform

Your organization requires that all new Cloud Storage buckets across all projects must be encrypted with customer-managed encryption keys (CMEK). As a Professional Cloud Security Engineer, how can you enforce this requirement using Google Cloud's organization policies?

  1. A

    Create a custom role with permissions to enforce CMEK, and assign it to all project owners.

  2. B

    Set the 'constraints/gcp.restrictCmekUsage' constraint at the organization level to require CMEK for all Cloud Storage buckets.

  3. C

    Enable the 'constraints/storage.requireCmek' organization policy at the project level for each project.

  4. D

    Configure a VPC Service Controls perimeter to enforce the use of CMEK for Cloud Storage buckets.

Show answer and explanation

Correct answer: B

Explanation

To enforce the use of CMEK for all Cloud Storage buckets across an organization, you need to use organization policies. Specifically, the 'constraints/gcp.restrictCmekUsage' constraint can enforce the requirement globally. This ensures that all buckets created within the organization adhere to the policy. Other approaches, such as using roles or VPC Service Controls, are not designed to enforce such constraints.

  • A. Incorrect.

    Incorrect. Creating a custom role does not enforce the use of CMEK. Organization policies, not roles, are used to enforce constraints across resources.

  • B. Correct.

    Correct. The 'constraints/gcp.restrictCmekUsage' organization policy can be set at the organization level to enforce the use of customer-managed encryption keys (CMEK) for Cloud Storage buckets across all projects.

  • C. Incorrect.

    Incorrect. While enabling the 'constraints/storage.requireCmek' policy at the project level might work, it does not enforce the requirement globally across the organization. Using the organization level ensures consistency.

  • D. Incorrect.

    Incorrect. VPC Service Controls are used for defining secure service perimeters to protect data, not for enforcing encryption key requirements.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam