Google Professional Data Engineer exam dumps

Google Professional Data Engineer practice question 79 of 279

Professional Data Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Data Engineer Question 79

Select 2Google Cloud Platform

You are responsible for designing a secure data pipeline for a financial services company on Google Cloud. The company requires that all sensitive data must be encrypted both at rest and in transit. Additionally, the encryption keys must be managed by the company itself using Google Cloud Key Management Service (KMS). Which of the following configurations would meet these requirements?

  1. A

    Use Google Cloud Storage with default encryption and enable TLS for data transfer.

  2. B

    Enable Customer-Managed Encryption Keys (CMEK) in Google Cloud Storage and use VPC Service Controls for data transfer.

  3. C

    Use Customer-Supplied Encryption Keys (CSEK) for encrypting data and ensure data transfer uses HTTPS.

  4. D

    Use Google Cloud Storage with CMEK and configure a Cloud Interconnect for secure on-premises data transfer.

  5. E

    Enable server-side encryption with Google-managed keys and restrict access using Identity and Access Management (IAM) policies.

Show answer and explanation

Correct answers: B, C

Explanation

To meet the requirements of encrypting sensitive data both at rest and in transit while managing encryption keys using the company's own infrastructure, the best options are using CMEK with Google Cloud KMS or using CSEK for full control of the encryption keys. Both of these approaches ensure customer-managed encryption while HTTPS or TLS ensures encryption in transit.

  • A. Incorrect.

    Default encryption in Google Cloud Storage secures data at rest, but it uses Google-managed keys by default, which does not meet the company's requirement to manage keys themselves. While TLS ensures secure data transfer, it does not fulfill the specific need for customer-managed encryption.

  • B. Correct.

    CMEK allows the company to manage its encryption keys using Google Cloud KMS, meeting the requirement for key management. VPC Service Controls provide additional security for data transfer, making this a valid option.

  • C. Correct.

    CSEK enables the company to supply and manage its own encryption keys, fully meeting the requirement for managing encryption keys. HTTPS for data transfer ensures encryption in transit, making this a valid choice.

  • D. Incorrect.

    Using CMEK ensures compliance with the customer-managed key requirement, but Cloud Interconnect is not necessary for encrypting data in transit, as HTTPS or TLS can suffice. This option partially meets the requirements but is not the best fit for the scenario.

  • E. Incorrect.

    Server-side encryption with Google-managed keys does not meet the requirement for customer-managed encryption keys. While IAM policies add access control, they do not address the need for encryption key management by the company.

Timed practice exam

Take a Google Professional Data Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam