Unlock the power of your data in the cloud! Get hands-on with Google Cloud's core data services like BigQuery and Looker to validate your practical skills in data ingestion, analysis, and management, and earn your Associate Data Practitioner certification!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise is storing sensitive customer analytics datasets across Google Cloud storage and data services, such as BigQuery and Cloud Storage. While Google Cloud encrypts all data at rest by default, the company's regulatory compliance mandate requires the security team to maintain direct control over key rotation schedules, audit key usage, and immediately revoke access to data by disabling keys if a security incident occurs.
Which encryption strategy should the organization implement to meet these compliance requirements?
Configure Essential Contacts to automatically alert the security team during key rotation events.
Rely on default Google-managed encryption keys with Identity and Access Management (IAM) controls.
Implement Customer-Managed Encryption Keys (CMEK) using Cloud Key Management Service (Cloud KMS).
Enable Access Transparency logs to monitor default encryption key access.
Configure Essential Contacts to automatically alert the security team during key rotation events.
Rely on default Google-managed encryption keys with Identity and Access Management (IAM) controls.
Implement Customer-Managed Encryption Keys (CMEK) using Cloud Key Management Service (Cloud KMS).
Customer-Managed Encryption Keys (CMEK) allow organizations to use Cloud Key Management Service (Cloud KMS) to create, manage, rotate, and control cryptographic keys that protect data stored at rest in Google Cloud services such as BigQuery, Cloud Storage, Cloud SQL, and Persistent Disk.
CMEK represents the industry-standard approach when organizations must comply with stringent regulatory frameworks that mandate customer control over encryption keys, while still leveraging the scalability, performance, and native functionality of Google Cloud managed services.
Enable Access Transparency logs to monitor default encryption key access.