Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise is establishing a data governance and encryption framework on Google Cloud to comply with strict regional data sovereignty and regulatory standards. The compliance baseline dictates the following technical requirements:
Which Cloud KMS configuration and lifecycle management strategy should the security architect specify?
Customer-Managed Encryption Keys (CMEK) hosted in Cloud Key Management Service (Cloud KMS) with the Cloud HSM protection level provide hardware-rooted FIPS 140-2 Level 3 cryptographic security. By creating key rings in a dedicated key management project, organizations enforce a strict separation of duties between KMS Administrators (who manage key lifecycles and IAM policies on keys) and Service Project Administrators (who manage storage and database resources).
This architecture establishes a robust governance model where key access, location constraints, and cryptographic lifecycles are centralized and secured without disrupting ongoing storage read and write operations.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.