Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 325 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 325

Single answerGoogle Cloud Platform

Your organization is storing sensitive customer data in Google Cloud Storage. The data must comply with strict regulatory requirements mandating that encryption keys remain under your organization's full control, even in the event of a Google Cloud breach. However, you also need to minimize operational overhead and ensure integration with Google Cloud services. Which encryption option should you choose?

  1. A

    Google default encryption

  2. B

    Customer-managed encryption keys (CMEK)

  3. C

    Cloud External Key Manager (Cloud EKM)

  4. D

    Unencrypted storage

Show answer and explanation

Correct answer: C

Explanation

The scenario requires encryption keys to remain under the organization's full control while ensuring compliance with strict regulatory requirements. Cloud External Key Manager (Cloud EKM) is the best option because it allows the organization to store and manage encryption keys outside of Google Cloud infrastructure, ensuring the highest level of control over encryption keys. Neither Google default encryption nor CMEK provides this level of control, and unencrypted storage is unsuitable for sensitive data.

  • A. Incorrect.

    Google default encryption automatically encrypts data at rest using encryption keys managed by Google. While secure, it does not provide control over encryption keys, which is required by the scenario.

  • B. Incorrect.

    Customer-managed encryption keys (CMEK) allow you to manage your own encryption keys using Cloud KMS. However, these keys are still stored and managed within Google Cloud, which does not fully meet the requirement of keeping keys entirely under your control.

  • C. Correct.

    Cloud External Key Manager (Cloud EKM) enables you to store and manage encryption keys outside of Google Cloud infrastructure, ensuring full control over the keys. This meets the regulatory requirement of keeping encryption keys outside the cloud provider's control.

  • D. Incorrect.

    Unencrypted storage is not a viable option as it does not meet security or compliance requirements for sensitive customer data.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam