Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise is migrating general application workloads, secrets, and log data to Google Cloud services such as Cloud Storage and Secret Manager. The enterprise's security policy mandates that all data at rest must satisfy NIST-approved baseline encryption standards, while the operations team wants to avoid the administrative burden of provisioning and managing custom key infrastructure.
Which statement accurately evaluates the underlying architecture, baseline security capabilities, and operational limitations of Google default encryption (Google-managed encryption keys)?
Google default encryption encrypts storage volumes using a single static root key provisioned inside Cloud KMS, allowing customers to view key access events in Cloud Audit Logs while delegating key lifecycle management to Google.
Google default encryption automatically applies AES-256 using envelope encryption via internal Keystore systems with zero customer overhead, but it offers no granular key-access audit logging, manual key rotation control, or ability to perform cryptographic erasure.
Google default encryption requires activating the constraints/gcp.restrictCmekCryptoKeyProjects organization policy, which restricts key storage to software protection levels within the local deployment region.
Google default encryption performs client-side data encryption prior to transit using the open-source Tink library, ensuring that cleartext data is never accessible to Google's internal production fleet.
Google default encryption encrypts storage volumes using a single static root key provisioned inside Cloud KMS, allowing customers to view key access events in Cloud Audit Logs while delegating key lifecycle management to Google.
Google default encryption automatically applies AES-256 using envelope encryption via internal Keystore systems with zero customer overhead, but it offers no granular key-access audit logging, manual key rotation control, or ability to perform cryptographic erasure.
Google default encryption (also known as Google-managed encryption keys or GMEK) is the baseline security control automatically enforced across all Google Cloud storage, database, and secret services. By default, raw customer data is split into chunks and encrypted at rest using AES-256 (or AES-128) with a unique Data Encryption Key (DEK). Google's internal infrastructure then uses envelope encryption to wrap each DEK with a Key Encryption Key (KEK) managed within Google's distributed, hardened Keystore and Root Keystore systems.
Google default encryption requires activating the constraints/gcp.restrictCmekCryptoKeyProjects organization policy, which restricts key storage to software protection levels within the local deployment region.
Google default encryption performs client-side data encryption prior to transit using the open-source Tink library, ensuring that cleartext data is never accessible to Google's internal production fleet.