Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A financial enterprise uses Cloud Key Management Service (Cloud KMS) to manage customer-managed encryption keys (CMEK) that protect sensitive workloads across multiple Google Cloud storage services. The enterprise uses envelope encryption where Cloud KMS manages the Key Encryption Keys (KEKs) that wrap individual Data Encryption Keys (DEKs).
To comply with regulatory standards and minimize the impact of potential key compromise, the security team needs to implement an automated key rotation schedule for their KEKs. They also must ensure that all previously stored data remains accessible after key rotation occurs.
What happens when an automated rotation schedule rotates a Cloud KMS key, and what administrative action is required to ensure existing data remains readable?
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.