🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 52 minutes remaining!

GCP Professional Cloud Architect Practice Question

Your fintech company is migrating its fraud-detection analytics to Google Cloud. Compliance mandates that all encryption keys be generated in, and remain in, an on-premises HSM; Google must never have access to the plaintext key material. Keys must rotate every 90 days without forcing re-encryption of existing BigQuery tables or Cloud Storage objects. The security operations team must control key lifecycle, while data engineers may only encrypt and decrypt data. Which approach best satisfies these requirements?

  • Generate a new key in Cloud HSM and export its material to the on-prem HSM for backup; enforce rotation by re-encrypting all existing data with each new key version and give security operations the Owner role on the projects.

  • Configure Cloud External Key Manager (EKM) with an externally managed key backed by the on-prem HSM; automate creation of a new external key version every 90 days, grant the security team the Cloud KMS Admin role, and grant data engineers the Cloud KMS CryptoKey Encrypter/Decrypter role.

  • Create a customer-managed symmetric key in Cloud KMS (software protection level), import the HSM-generated material into a new key version every 90 days, and make data engineers key Owners for direct management.

  • Store the HSM-generated key in Secret Manager and rotate it by updating the secret every 90 days; have data engineers retrieve the secret at runtime to encrypt and decrypt data.

GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot