Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A security engineer is designing a Customer-Managed Encryption Key (CMEK) lifecycle strategy for sensitive enterprise workloads hosted in Google Cloud. Company security compliance mandates that encryption keys must automatically rotate every 90 days.
The engineer must configure the CMEK keys and dependent cloud resources so that:
Which configuration strategy should the engineer implement?
Customer-Managed Encryption Keys (CMEK) in Google Cloud allow organizations to manage symmetric encryption keys inside Cloud Key Management Service (Cloud KMS) to protect data at rest across managed services. When configuring a CryptoKey, administrators can define an automated rotation period (such as 90 days) alongside a next rotation time.
projects/PROJECT_ID/locations/LOCATION/keyRings/KEY_RING/cryptoKeys/KEY_NAME) rather than a specific version ID. The resource automatically uses the current primary key version for all new write operations.This architecture adheres strictly to Google Cloud security best practices by decoupling the key resource path from individual version numbers while maintaining seamless read access to older ciphertext versions.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.