Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A financial services organization is designing a regulatory compliance architecture for data encryption in Google Cloud. Compliance auditors require proof that master encryption keys meet three specific criteria:
How do Cloud KMS software-backed keys differ from Cloud HSM hardware-backed keys regarding key generation, isolation models, and attestation capabilities to satisfy these requirements?
Google Cloud Key Management Service (Cloud KMS) provides cryptographic key management across multiple protection levels. Keys configured with the software protection level (SOFTWARE) run on standard production server infrastructure, whereas keys configured with the hardware security module protection level (HSM) operate inside dedicated, tamper-resistant FIPS 140-2 Level 3 validated hardware security modules.
0x0163 creation origin and non-extractability flags) and is cryptographically verifiable using certificate chains rooted in both Google and the HSM manufacturer (Marvell LiquidSecurity).CryptoKeys, CryptoKeyVersions) as software keys, requiring zero application logic redesign.Software-backed keys provide robust encryption at rest managed across Google production fleets, but they execute operations in host RAM using software cryptographic modules (such as BoringCrypto) and do not produce hardware-rooted cryptographic attestation statements. Only Cloud HSM provides the physical isolation, strict non-extractability enforcement, and dual-rooted attestation required by stringent regulatory standards.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.