professional-cloud-data-engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Your organization is designing an enterprise data analytics platform in Google Cloud that processes highly regulated healthcare data across Cloud Storage and BigQuery.
Your security and compliance policies dictate the following requirements:
Which architecture and configuration strategy should you implement?
This architecture establishes a secure, centrally governed Customer-Managed Encryption Key (CMEK) deployment using Cloud KMS with Cloud HSM across dedicated Google Cloud projects to enforce cryptographic isolation and administrative separation of duties.
KEY_PROJECT_ID distinct from the data analytics and storage projects ensures that data engineers who manage datasets and buckets do not hold administrative IAM permissions (roles/cloudkms.admin) over the keys.roles/cloudkms.cryptoKeyEncrypterDecrypter directly to the BigQuery and Cloud Storage service accounts enables transparent server-side envelope encryption and decryption.This approach aligns with Google Cloud security best practices by combining isolated project boundaries for key management, hardware-backed keys, and automatic default key inheritance at the dataset and bucket scope, ensuring consistent protection without operational overhead.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.