Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A financial enterprise is deploying sensitive workloads to Google Cloud and must satisfy strict data sovereignty and jurisdictional isolation regulations. The enterprise security policy requires that the root-of-trust encryption keys reside exclusively within on-premises Hardware Security Modules (HSMs) outside Google Cloud. Furthermore, all cryptographic communication between Google Cloud services and the on-premises key management systems must traverse private network paths without traversing the public internet, while supporting automated failover between dual on-premises data centers.
Which Cloud External Key Manager (Cloud EKM) architecture should the organization implement?
Configure Cloud EKM over a VPC network using an internal passthrough Network Load Balancer and regional Cloud KMS key rings.
Configure Cloud EKM over the internet using an external proxy Network Load Balancer and multi-regional Cloud KMS key rings.
Configure Cloud EKM over a VPC network using direct hybrid connectivity and multi-regional Cloud KMS key rings.
Deploy Single-tenant Cloud HSM instances with VPC Service Controls perimeter restrictions.
Configure Cloud EKM over a VPC network using an internal passthrough Network Load Balancer and regional Cloud KMS key rings.
Cloud External Key Manager (Cloud EKM) over a VPC network enables Google Cloud services to protect data at rest using encryption keys maintained directly inside a customer's external, on-premises key management infrastructure. Instead of sending requests across the public internet, cryptographic requests travel over private hybrid connectivity such as Cloud Interconnect or HA VPN.
This architecture satisfies both sovereign key custody outside Google Cloud and strict network perimeter requirements by pairing private hybrid connectivity with an internal load balancer in a regional configuration.
Configure Cloud EKM over the internet using an external proxy Network Load Balancer and multi-regional Cloud KMS key rings.
Configure Cloud EKM over a VPC network using direct hybrid connectivity and multi-regional Cloud KMS key rings.
Deploy Single-tenant Cloud HSM instances with VPC Service Controls perimeter restrictions.