Google Professional Data Engineer exam dumps

Google Professional Data Engineer practice question 7 of 279

Professional Data Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Data Engineer Question 7

Single answerGoogle Cloud Platform

You are designing a data pipeline on Google Cloud to process sensitive customer data. As part of the security requirements, you need to ensure that all stored data is encrypted and that encryption keys are managed in a way that allows you full control over them. Which approach should you choose to meet these requirements?

  1. A

    Use default Google-managed encryption for data at rest.

  2. B

    Use Customer-Managed Encryption Keys (CMEK) with Cloud Key Management Service (KMS).

  3. C

    Manually encrypt the data using an external encryption library before storing it in Google Cloud Storage.

  4. D

    Use Customer-Supplied Encryption Keys (CSEK) for encrypting data at rest.

Show answer and explanation

Correct answer: B

Explanation

Customer-Managed Encryption Keys (CMEK) with Cloud KMS is the best approach to meet the requirements of encrypting data and maintaining full control over the encryption keys. CMEK ensures that you have centralized control over your keys, including key rotation and access policies, while benefiting from integration with Google Cloud services. Other options either do not provide full control over the keys or introduce unnecessary complexity.

  • A. Incorrect.

    Google-managed encryption is the default option in Google Cloud, but it does not provide full control over encryption keys as the keys are managed entirely by Google.

  • B. Correct.

    Customer-Managed Encryption Keys (CMEK) with Cloud KMS allows you to use your own encryption keys stored in Google Cloud Key Management Service, giving you full control over key rotation and access policies.

  • C. Incorrect.

    Manually encrypting data using an external library introduces operational complexity and is generally not recommended unless there are specific requirements that cannot be met with integrated Google Cloud encryption features.

  • D. Incorrect.

    Customer-Supplied Encryption Keys (CSEK) allow you to supply your own keys, but they are not stored or managed by Google Cloud, making key management more complex and potentially less secure.

Timed practice exam

Take a Google Professional Data Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam