Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise is migrating general application workloads, secrets, and log data to Google Cloud services such as Cloud Storage and Secret Manager. The enterprise's security policy mandates that all data at rest must satisfy NIST-approved baseline encryption standards, while the operations team wants to avoid the administrative burden of provisioning and managing custom key infrastructure.
Which statement accurately evaluates the underlying architecture, baseline security capabilities, and operational limitations of Google default encryption (Google-managed encryption keys)?
Google default encryption (also known as Google-managed encryption keys or GMEK) is the baseline security control automatically enforced across all Google Cloud storage, database, and secret services. By default, raw customer data is split into chunks and encrypted at rest using AES-256 (or AES-128) with a unique Data Encryption Key (DEK). Google's internal infrastructure then uses envelope encryption to wrap each DEK with a Key Encryption Key (KEK) managed within Google's distributed, hardened Keystore and Root Keystore systems.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.