Unlock the power of your data in the cloud! Get hands-on with Google Cloud's core data services like BigQuery and Looker to validate your practical skills in data ingestion, analysis, and management, and earn your Associate Data Practitioner certification!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A financial services organization is designing a data storage architecture on Google Cloud. The company's compliance policy mandates that the security team must maintain direct administrative control over encryption key lifecycles—including key creation, rotation schedules, and immediate key revocation—directly through Google Cloud's centralized key management service, while allowing cloud storage services to automatically handle encryption and decryption operations.
Which encryption key management strategy should the organization implement?
Customer-managed encryption keys (CMEK) allow organizations to control and manage the symmetric encryption keys used to protect data at rest within supported Google Cloud services. The cryptographic keys reside in and are managed through Cloud Key Management Service (Cloud KMS) or Cloud HSM, giving the customer control over administrative operations while allowing the target Google Cloud service to use the keys via service accounts.
CMEK provides the perfect balance between regulatory compliance and operational simplicity. Unlike Google-managed keys, the customer maintains complete authority over key lifecycle and revocation. Unlike client-side or customer-supplied keys, CMEK integrates natively with GCP services without requiring developers to manage key material during every API request or handle encryption client-side.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.