Google Professional Data Engineer exam dumps

Google Professional Data Engineer practice question 8 of 279

Professional Data Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Data Engineer Question 8

Single answerGoogle Cloud Platform

You are designing a data pipeline on Google Cloud that processes sensitive customer information. To meet regulatory compliance requirements, you need to ensure that the data is encrypted at rest and that the encryption keys are managed securely. Which approach would best meet these requirements?

  1. A

    Use Google Cloud Storage with default encryption and let Google manage the encryption keys.

  2. B

    Use Google Cloud Storage Customer-Managed Encryption Keys (CMEK) and store the keys in Cloud Key Management Service (Cloud KMS).

  3. C

    Use Google Cloud Storage and manually encrypt the data before uploading it, storing the encryption keys in a secure on-premises server.

  4. D

    Use Google Cloud Storage with default encryption, and periodically rotate the encryption keys manually.

Show answer and explanation

Correct answer: B

Explanation

Customer-Managed Encryption Keys (CMEK) with Cloud KMS is the best option because it provides strong encryption at rest and allows you to manage your encryption keys, meeting both security and regulatory compliance requirements. This approach strikes a balance between control over your keys and leveraging Google Cloud's built-in security features.

  • A. Incorrect.

    Using Google Cloud Storage with default encryption relies on Google-managed encryption keys. While secure, it does not provide the level of key management required for regulatory compliance in many cases.

  • B. Correct.

    Using Customer-Managed Encryption Keys (CMEK) with Cloud KMS allows you to control and manage your encryption keys while leveraging the security and scalability of Google Cloud. This approach meets the requirements for encryption at rest and secure key management.

  • C. Incorrect.

    Manually encrypting the data before uploading it and storing the keys on-premises can be complex and error-prone. It also does not leverage the built-in security features of Google Cloud, making it harder to manage and audit.

  • D. Incorrect.

    Default encryption with manual key rotation is not a supported approach in Google Cloud. Key rotation is automatically managed by Google in default encryption, and there is no manual rotation option.

Timed practice exam

Take a Google Professional Data Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam