Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A financial enterprise is deploying a mission-critical workload on Google Cloud to handle sensitive federal financial records and payment card transaction data. The organization's compliance officer determines that the cryptographic architecture must satisfy both FedRAMP High and PCI DSS standards, specifically mandating that cryptographic keys protecting data at rest be hosted inside cryptographic modules certified to FIPS 140-2 Level 3 for physical tamper resistance.
Which cryptographic key protection configuration in Google Cloud Key Management Service (Cloud KMS) should the security engineer deploy to fulfill these regulatory mandates while retaining native integration with Google Cloud services?
Cloud HSM (Hardware Security Module) is a fully managed, cloud-hosted hardware security module service integrated directly into Google Cloud KMS. When keys are created with the HSM protection level, all cryptographic operations and key generation routines occur strictly inside dedicated hardware devices certified to FIPS 140-2 Level 3.
Using Cloud KMS with the HSM protection level directly satisfies the stringent FIPS 140-2 Level 3 requirements for hardware isolation while preserving the automated lifecycle, scaling, and deep service integrations of native Google Cloud CMEK workflows.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.