Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 320 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 320

Select 3Google Cloud Platform

You are designing a secure data storage solution for a financial services application on Google Cloud. The application processes sensitive customer information, and compliance requirements mandate that data must be encrypted at rest, in transit, and in use. Which of the following measures should you implement to meet these requirements?

  1. A

    Use Cloud Key Management Service (KMS) to manage and rotate encryption keys for data at rest.

  2. B

    Enable TLS encryption for all connections between clients and the application.

  3. C

    Store sensitive data in plaintext in Google Cloud Storage buckets to improve performance.

  4. D

    Leverage Confidential VMs to ensure data remains encrypted while being processed in memory.

  5. E

    Use default encryption for Google Cloud Storage buckets without any additional configuration.

Show answer and explanation

Correct answers: A, B, D

Explanation

To meet the requirements for encryption at rest, in transit, and in use, you must implement a combination of measures. Cloud KMS enables encryption at rest with key management and rotation. TLS ensures secure encryption for data in transit. Confidential VMs address the encryption-in-use requirement by keeping data encrypted while it is processed in memory. Storing data in plaintext or relying solely on default encryption without additional controls would not satisfy compliance mandates.

  • A. Correct.

    This is correct. Cloud Key Management Service (KMS) allows you to manage and rotate encryption keys, ensuring that data at rest is encrypted using strong cryptographic standards.

  • B. Correct.

    This is correct. Enabling TLS ensures that data in transit is encrypted, protecting it from interception during transmission.

  • C. Incorrect.

    This is incorrect. Storing sensitive data in plaintext violates security best practices and compliance requirements, even if it may improve performance.

  • D. Correct.

    This is correct. Confidential VMs ensure that data remains encrypted even while being processed in memory, addressing the encryption-in-use requirement.

  • E. Incorrect.

    This is incorrect. While Google Cloud Storage provides default encryption, additional measures such as key management and custom encryption policies may be required to comply with strict compliance mandates.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam