🔥 40% Off Crucial Exams Memberships — Deal ends today!

10 minutes, 51 seconds remaining!

GCP Professional Cloud Architect Practice Question

Your organization is launching a multi-tenant analytics SaaS on Google Cloud that ingests and stores telemetry data from customer IoT devices. Raw data lands in Cloud Storage and is transformed into BigQuery tables for reporting. The data is not subject to industry regulations that mandate customer control of cryptographic keys, but customers expect all data at rest to be encrypted. The operations team must minimize day-to-day key lifecycle tasks and avoid introducing any new dependencies that could reduce availability. Which key-management approach should you recommend?

  • Deploy an on-premises Hardware Security Module and integrate it with Cloud External Key Manager so that encryption keys never reside in Google Cloud.

  • Create Customer-Managed Encryption Keys (CMEK) in Cloud KMS and schedule automatic rotation every 90 days for all buckets and datasets.

  • Rely on Google-managed encryption keys, which provide default at-rest encryption for Cloud Storage and BigQuery and are automatically created, stored, and rotated by Google without additional effort.

  • Require each workload to supply Customer-Supplied Encryption Keys (CSEK) on every write request and rotate the keys monthly.

GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot