Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A financial enterprise is deploying sensitive workloads to Google Cloud and must satisfy strict data sovereignty and jurisdictional isolation regulations. The enterprise security policy requires that the root-of-trust encryption keys reside exclusively within on-premises Hardware Security Modules (HSMs) outside Google Cloud. Furthermore, all cryptographic communication between Google Cloud services and the on-premises key management systems must traverse private network paths without traversing the public internet, while supporting automated failover between dual on-premises data centers.
Which Cloud External Key Manager (Cloud EKM) architecture should the organization implement?
Cloud External Key Manager (Cloud EKM) over a VPC network enables Google Cloud services to protect data at rest using encryption keys maintained directly inside a customer's external, on-premises key management infrastructure. Instead of sending requests across the public internet, cryptographic requests travel over private hybrid connectivity such as Cloud Interconnect or HA VPN.
This architecture satisfies both sovereign key custody outside Google Cloud and strict network perimeter requirements by pairing private hybrid connectivity with an internal load balancer in a regional configuration.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.