Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise is architecting a high-throughput, low-latency transaction processing platform on Google Cloud using managed services such as Firestore in Datastore mode and Dataproc Metastore across the us multi-region. The security engineering team must establish a key management architecture that satisfies several operational and architectural requirements:
Which cryptographic key management architecture should the organization implement to fulfill these requirements?
Deploy Cloud External Key Manager (Cloud EKM) keys hosted in an on-premises hardware security module connected over Cloud Interconnect.
Configure symmetric Cloud KMS keys with Software or Cloud HSM protection levels in locations that match the resource regions and multi-regions.
Create a single global Cloud KMS key and use it uniformly across all regional and multi-regional managed resources.
Implement client-side encryption using asymmetric Cloud KMS RSA keys to encrypt every transactional field before sending it to the database API.
Deploy Cloud External Key Manager (Cloud EKM) keys hosted in an on-premises hardware security module connected over Cloud Interconnect.
Configure symmetric Cloud KMS keys with Software or Cloud HSM protection levels in locations that match the resource regions and multi-regions.
Google Cloud Key Management Service (Cloud KMS) provides managed symmetric key encryption keys (KEKs) hosted either in software or within hardware security modules (Cloud HSM). These keys integrate natively with Google Cloud services to provide Customer-Managed Encryption Keys (CMEK) while maintaining low latency and high availability.
us multi-region), removing external network dependencies.us multi-region mapped to Datastore nam5), satisfying strict location validation rules.roles/cloudkms.cryptoKeyEncrypterDecrypter to specific Google-managed service agents.Choosing in-cloud Software or Cloud HSM keys avoids the latency, availability risks, and external egress dependencies of external key managers while ensuring full CMEK compatibility across all Google Cloud services.
Create a single global Cloud KMS key and use it uniformly across all regional and multi-regional managed resources.
Implement client-side encryption using asymmetric Cloud KMS RSA keys to encrypt every transactional field before sending it to the database API.