Unlock the power of your data in the cloud! Get hands-on with Google Cloud's core data services like BigQuery and Looker to validate your practical skills in data ingestion, analysis, and management, and earn your Associate Data Practitioner certification!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A financial services organization is designing a data storage architecture on Google Cloud to store sensitive transaction records. The organization's security policy defines the following compliance and operational requirements:
Which encryption key management approach should the organization implement?
Customer-managed encryption keys (CMEK) allow organizations to use Cloud Key Management Service (Cloud KMS) to create, manage, rotate, and control the cryptographic keys used to protect data at rest across Google Cloud services. While Google Cloud encrypts all customer content at rest by default, CMEK gives customers direct administrative control over the root keys that protect the data encryption keys.
constraints/gcp.restrictNonCmekServices (blocking creation of resources without CMEK) and constraints/gcp.restrictCmekCryptoKeyProjects (limiting authorized KMS key projects).roles/cloudkms.cryptoKeyEncrypterDecrypter and roles/cloudkms.admin.CMEK strikes the ideal balance between regulatory compliance, centralized control, and operational simplicity. It fulfills strict audit and key governance requirements while retaining seamless cloud automation.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.