Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 326 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 326

Single answerGoogle Cloud Platform

Your organization stores sensitive customer data in Google Cloud Storage. Due to compliance requirements, you need to ensure that encryption keys used for data encryption are managed offsite and under your full control. Which encryption option should you choose?

  1. A

    Google default encryption

  2. B

    Customer-managed encryption keys (CMEK)

  3. C

    Cloud External Key Manager (EKM)

  4. D

    Client-side encryption

Show answer and explanation

Correct answer: C

Explanation

Cloud External Key Manager (EKM) is the correct choice because it allows organizations to store and manage encryption keys outside of Google Cloud infrastructure. This is ideal for meeting compliance requirements where keys must be managed offsite and under full customer control. Default encryption, CMEK, and client-side encryption either don't meet the offsite key management requirement or are not applicable to the scenario.

  • A. Incorrect.

    Google default encryption is the default option provided by Google Cloud, where Google manages the encryption keys entirely. This does not satisfy the compliance requirement to manage keys offsite.

  • B. Incorrect.

    Customer-managed encryption keys (CMEK) allow you to manage your own keys using Cloud Key Management Service (KMS), but the keys are still stored and managed within Google Cloud, which does not meet the requirement of offsite key control.

  • C. Correct.

    Cloud External Key Manager (EKM) allows you to store and manage encryption keys outside of Google Cloud using an external key management system. This satisfies the compliance requirement for offsite key control.

  • D. Incorrect.

    Client-side encryption involves encrypting data on the client-side before sending it to Google Cloud, but this is not directly tied to Google Cloud's encryption key management options and is not required in this specific scenario.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam