🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 50 minutes remaining!

GCP Professional Cloud Architect Practice Question

A government agency is migrating tens of terabytes of scanned legal records to Compute Engine persistent disks. Compliance policy states:

  1. Google Cloud must never retain any copy-encrypted or plaintext-of the encryption key.
  2. Security officers must be able to make the data permanently unreadable at any moment by deleting their local key material, without invoking any additional Google Cloud APIs.

Which data-at-rest encryption approach best satisfies these requirements?

  • Use CMEK with Cloud External Key Manager backed by an on-premises HSM.

  • Use customer-managed encryption keys (CMEK) stored in Cloud KMS and rotate them manually on demand.

  • Rely on Google-managed default encryption for persistent disks, which encrypts data without any customer-side keys.

  • Use customer-supplied encryption keys (CSEK) and provide the key in every Compute Engine API request that touches the disks.

GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot