Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 337 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 337

Select 3Google Cloud Platform

A financial services company is using Google Cloud and has configured a Cloud Storage bucket with a Customer-Managed Encryption Key (CMEK) stored in Cloud Key Management Service (Cloud KMS). To comply with a regulatory requirement, they must rotate encryption keys every 6 months. Additionally, the company plans to transition to an External Key Management (EKM) system in the future. What steps should they take to rotate the CMEK and prepare for the EKM setup?

  1. A

    Create a new key version in Cloud KMS and update the CMEK configuration in the Cloud Storage bucket to use the new key version.

  2. B

    Re-encrypt all existing data in the Cloud Storage bucket using the new key version after key rotation.

  3. C

    Verify that the EKM provider supports Cloud EKM integration and configure the necessary connectivity between Cloud KMS and the EKM provider.

  4. D

    Delete the old encryption key immediately after configuring the new CMEK version to ensure security.

  5. E

    Update IAM permissions on the new key version to match the permissions of the previous version.

Show answer and explanation

Correct answers: A, C, E

Explanation

To rotate a CMEK in Google Cloud, you create a new key version, update the resource to use the new version, and ensure IAM permissions are consistent. For transitioning to an EKM system, you need to verify the EKM provider's compatibility and set up connectivity between Cloud KMS and the provider. Deleting old keys or manually re-encrypting data are unnecessary steps that can lead to operational risks or inefficiencies.

  • A. Correct.

    Correct: When rotating a CMEK in Cloud KMS, you create a new key version and update the resource using the CMEK to point to the new key version. This ensures proper key rotation without disrupting operations.

  • B. Incorrect.

    Incorrect: Re-encrypting all data manually is not necessary because Google Cloud handles data encryption and decryption transparently when you update the CMEK configuration with a new key version.

  • C. Correct.

    Correct: Preparing for an EKM setup requires verifying that the external key provider supports Cloud EKM integration and ensuring proper connectivity. This step is crucial for transitioning to an EKM system.

  • D. Incorrect.

    Incorrect: Deleting the old key immediately is not recommended, as it might still be needed for decrypting previously encrypted data. Google Cloud recommends retaining old key versions for decryption purposes.

  • E. Correct.

    Correct: Updating IAM permissions ensures that users and services can access the new key version without any disruption. Permissions should be consistent with the previous version unless specific changes are required.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam