Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 328 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 328

Single answerGoogle Cloud Platform

Your organization is migrating a sensitive financial application to Google Cloud. The application handles highly sensitive customer data, and your compliance team requires full control over encryption keys. Additionally, the compliance policy mandates that encryption keys must not reside in Google Cloud but be managed externally. Which encryption solution should you choose to meet these requirements?

  1. A

    Google default encryption

  2. B

    Customer-managed encryption keys (CMEK)

  3. C

    Cloud External Key Manager (EKM)

  4. D

    Customer-supplied encryption keys (CSEK)

Show answer and explanation

Correct answer: C

Explanation

The correct answer is Cloud External Key Manager (EKM) because it enables organizations to manage their encryption keys externally while still integrating with Google Cloud services. This satisfies the compliance policy requiring that encryption keys must not reside in Google Cloud and provides the necessary control for sensitive financial applications. Other options either do not allow external key management (Google default encryption, CMEK) or do not fully integrate with Google Cloud (CSEK).

  • A. Incorrect.

    Google default encryption automatically encrypts data at rest using Google-managed keys. However, it does not provide the level of control over encryption keys or the external key management required by the compliance policy.

  • B. Incorrect.

    Customer-managed encryption keys (CMEK) allow you to manage encryption keys in Google Cloud's Key Management Service (KMS). While CMEK provides more control over keys compared to default encryption, it does not satisfy the requirement for external key management.

  • C. Correct.

    Cloud External Key Manager (EKM) allows you to manage keys outside of Google Cloud while still integrating with Google Cloud services for encryption. This solution meets the compliance requirement of managing encryption keys externally.

  • D. Incorrect.

    Customer-supplied encryption keys (CSEK) allow you to encrypt data using keys stored outside Google Cloud. However, this approach does not integrate with Google Cloud KMS and may not be as suitable for enterprise-scale use cases requiring external key management.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam