Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise is establishing a data governance and encryption framework on Google Cloud to comply with strict regional data sovereignty and regulatory standards. The compliance baseline dictates the following technical requirements:
Which Cloud KMS configuration and lifecycle management strategy should the security architect specify?
Provision Cloud HSM-backed CMEK keys in a dedicated key management project in the same region as the data services, rotate keys by generating a new primary key version, and maintain older key versions in an enabled state.
Deploy software-backed Cloud KMS keys inside the existing application project, initiate key rotation, and rely on automated background re-encryption of historical data with the new primary key version.
Configure Cloud External Key Manager (Cloud EKM) with manual rotation policies, and schedule automatic key version destruction immediately upon promoting a new primary version.
Provision Cloud HSM-backed CMEK keys in a multi-region key ring, create a new primary key version during rotation, and immediately disable previous key versions to prevent legacy cryptographic operations.
Provision Cloud HSM-backed CMEK keys in a dedicated key management project in the same region as the data services, rotate keys by generating a new primary key version, and maintain older key versions in an enabled state.
Customer-Managed Encryption Keys (CMEK) hosted in Cloud Key Management Service (Cloud KMS) with the Cloud HSM protection level provide hardware-rooted FIPS 140-2 Level 3 cryptographic security. By creating key rings in a dedicated key management project, organizations enforce a strict separation of duties between KMS Administrators (who manage key lifecycles and IAM policies on keys) and Service Project Administrators (who manage storage and database resources).
This architecture establishes a robust governance model where key access, location constraints, and cryptographic lifecycles are centralized and secured without disrupting ongoing storage read and write operations.
Deploy software-backed Cloud KMS keys inside the existing application project, initiate key rotation, and rely on automated background re-encryption of historical data with the new primary key version.
Configure Cloud External Key Manager (Cloud EKM) with manual rotation policies, and schedule automatic key version destruction immediately upon promoting a new primary version.
Provision Cloud HSM-backed CMEK keys in a multi-region key ring, create a new primary key version during rotation, and immediately disable previous key versions to prevent legacy cryptographic operations.