Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam Professional Cloud Security Engineer topic 1 question 161 discussion

Actual exam question from Google's Professional Cloud Security Engineer
Question #: 161
Topic #: 1
[All Professional Cloud Security Engineer Questions]

You are implementing data protection by design and in accordance with GDPR requirements. As part of design reviews, you are told that you need to manage the encryption key for a solution that includes workloads for Compute Engine, Google Kubernetes Engine, Cloud Storage, BigQuery, and Pub/Sub. Which option should you choose for this implementation?

  • A. Cloud External Key Manager
  • B. Customer-managed encryption keys
  • C. Customer-supplied encryption keys
  • D. Google default encryption
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
zellck
Highly Voted 1 year, 7 months ago
Selected Answer: B
B is the answer. https://cloud.google.com/kms/docs/using-other-products#cmek_integrations https://cloud.google.com/kms/docs/using-other-products#cmek_integrations CMEK is supported for all the listed google services.
upvoted 16 times
...
Littleivy
Highly Voted 1 year, 6 months ago
Selected Answer: A
Obviously A is the better answer. Based on the GCP blog [1], you can utilize Cloud External Key Manager (Cloud EKM) to manage customer key easily and fulfill the compliance requirements as Key Access Justifications is already GA. Also, Cloud EKM supports all the services listed in the questions per the reference [2] [1] https://cloud.google.com/blog/products/compliance/how-google-cloud-helps-customers-stay-current-with-gdpr [2] https://cloud.google.com/kms/docs/ekm#supported_services
upvoted 11 times
gcpengineer
1 year ago
unfortunately not supported for all services
upvoted 1 times
orcnylmz
10 months, 2 weeks ago
All services mentioned in the question are supported by EKM https://cloud.google.com/kms/docs/ekm#supported_services
upvoted 2 times
...
...
...
Roro_Brother
Most Recent 1 week, 5 days ago
Selected Answer: B
B is the answer. https://cloud.google.com/kms/docs/using-other-products#cmek_integrations https://cloud.google.com/kms/docs/using-other-products#cmek_integrations CMEK is supported for all the listed google services.
upvoted 1 times
...
Roro_Brother
1 week, 6 days ago
Selected Answer: B
B. Customer-managed encryption keys With customer-managed encryption keys (CMEK), you have control over the encryption keys used to protect your data in Google Cloud Platform services such as Compute Engine, Google Kubernetes Engine, Cloud Storage, BigQuery, and Pub/Sub. This ensures that you can manage and control the keys in a way that aligns with GDPR requirements and provides an additional layer of security for your data.
upvoted 1 times
...
Bettoxicity
1 month, 2 weeks ago
Selected Answer: B
B Why not A?: GCP doesn't offer a service called "Cloud External Key Manager." While there are external key management solutions, they might not integrate seamlessly with all GCP services you're using.
upvoted 1 times
...
glb2
1 month, 4 weeks ago
Selected Answer: B
B. Customer-managed encryption keys With customer-managed encryption keys (CMEK), you have control over the encryption keys used to protect your data in Google Cloud Platform services such as Compute Engine, Google Kubernetes Engine, Cloud Storage, BigQuery, and Pub/Sub. This ensures that you can manage and control the keys in a way that aligns with GDPR requirements and provides an additional layer of security for your data.
upvoted 1 times
...
dija123
2 months, 1 week ago
Selected Answer: B
All mentioned services are supported by CMEK
upvoted 1 times
...
Nachtwaker
2 months, 1 week ago
Selected Answer: B
A or B, where B does not require additional assets/resources and thus (sounds like it would be) cheaper
upvoted 2 times
...
b6f53d8
3 months, 3 weeks ago
I work with banks in Eu, they are using CMEK in general and it is GDPR compliant - B
upvoted 1 times
...
hakunamatataa
7 months, 4 weeks ago
Selected Answer: A
With my current client in Europe, where GDPR is mandate, we are using EKM.
upvoted 3 times
...
[Removed]
9 months, 4 weeks ago
Selected Answer: A
Seems to be EKM in conjunction with CMEK to support all the required services. However it's EKM specifically that enables customers to store keys in europe and enforce various controls over their keys as required by GDPR. https://cloud.google.com/blog/products/compliance/how-google-cloud-helps-customers-stay-current-with-gdpr https://cloud.google.com/kms/docs/using-other-products#cmek_integrations
upvoted 4 times
...
TNT87
1 year, 1 month ago
Selected Answer: B
Cloud External Key Manager (option A) is an option for customers who require full control over their encryption keys while leveraging Google Cloud's Key Management Service. However, this option is generally not required for GDPR compliance.
upvoted 3 times
TNT87
1 year, 1 month ago
https://cloud.google.com/kms/docs/compatible-services#cmek_integrations
upvoted 1 times
...
...
alleinallein
1 year, 1 month ago
Selected Answer: A
EKM is GDPR compliant
upvoted 1 times
...
Examster1
1 year, 3 months ago
Answer is A and please read the docs. Cloud EKM is GDPR compliant and does support all the services listed. Where is the confusion here?
upvoted 4 times
gcpengineer
1 year ago
It doesn't
upvoted 1 times
...
...
marmar11111
1 year, 6 months ago
Selected Answer: B
"Customer-supplied encryption keys (CSEK) are a feature in Google Cloud Storage and Google Compute Engine. If you supply your own encryption keys, Google uses your key to protect the Google-generated keys used to encrypt and decrypt your data." so it can't be A because A doesn't support all these services. The answer is B as this still allows you to manage your keys!
upvoted 6 times
...
GHOST1985
1 year, 6 months ago
Selected Answer: A
https://cloud.google.com/blog/products/compliance/how-google-cloud-helps-customers-stay-current-with-gdpr
upvoted 5 times
...
Table2022
1 year, 6 months ago
Answer is A, Customers can also require detailed justification and approval each time a key is requested to decrypt data using External Key Manager, and deny Google the ability to decrypt their data for any reason using Key Access Justifications, which is now in General Availability. https://cloud.google.com/blog/products/compliance/how-google-cloud-helps-customers-stay-current-with-gdpr
upvoted 6 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...