Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 330 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 330

Single answerGoogle Cloud Platform

Your organization needs to implement key management for a sensitive financial application hosted on Google Cloud. The application requires high-performance cryptographic operations for large-scale workloads and must meet strict compliance requirements. Additionally, the organization needs to ensure that the keys are stored securely and cannot be exported. Which key management solution should you choose?

  1. A

    Use Cloud KMS with software keys stored in Google-managed infrastructure.

  2. B

    Use Cloud HSM to generate and store hardware-protected keys.

  3. C

    Use external key management via Cloud EKM with keys stored in an on-premises HSM.

  4. D

    Use customer-provided software keys stored in a Compute Engine instance.

Show answer and explanation

Correct answer: B

Explanation

Cloud HSM is the best solution for this scenario because it combines hardware protection with high-performance cryptographic operations and meets strict compliance requirements. It ensures the keys are securely stored and cannot be exported, aligning with the needs of the financial application.

  • A. Incorrect.

    Cloud KMS with software keys is suitable for general-purpose key management, but it does not meet the requirement of hardware protection and may not be sufficient for strict compliance use cases.

  • B. Correct.

    Cloud HSM is the appropriate choice because it uses FIPS 140-2 Level 3 certified hardware to securely generate and store keys. It meets high compliance standards and ensures keys cannot be exported.

  • C. Incorrect.

    Cloud EKM with an on-premises HSM is useful when organizations want to manage keys outside of Google Cloud for specific regulatory reasons, but it may introduce latency and does not provide the high-performance cryptographic operations required in this scenario.

  • D. Incorrect.

    Customer-provided software keys stored in a Compute Engine instance do not offer the necessary security guarantees, as they are not hardware-protected and may be vulnerable to compromise.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam