Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise security architect must establish a secure key lifecycle process to import on-premises generated 256-bit AES symmetric keys into Google Cloud KMS for use with Customer-Managed Encryption Keys (CMEK) across Cloud Storage and BigQuery.
The solution must satisfy the following requirements:
Which end-to-end workflow and authorization strategy should the architect implement?
This workflow establishes a secure Bring Your Own Key (BYOK) lifecycle within Google Cloud KMS by manually preparing an empty target key, generating an ephemeral Import Job protected by Cloud HSM, cryptographically wrapping the key material on-premises, importing it, activating it as the primary version, and delegating cryptographic usage permissions to Google Cloud service agents.
HSM protection level, the private unwrapping key portion resides strictly within Google Cloud HSMs and cannot be accessed outside the hardware boundary.service-PROJECT_NUMBER@gs-project-accounts.iam.gserviceaccount.com). Granting roles/cloudkms.cryptoKeyEncrypterDecrypter directly to these service agents—rather than human administrators or end users—enforces least privilege and strict role separation.roles/cloudkms.admin) from encryption/decryption execution.This procedure fully aligns with Google Cloud key import specifications, guarantees end-to-end envelope protection during transit, ensures active CMEK utilization, and satisfies strict regulatory separation-of-duties standards.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.