🔥 40% Off Crucial Exams Memberships — Deal ends today!

9 minutes, 57 seconds remaining!

GCP Professional Cloud Security Engineer Practice Question

A financial-services company is migrating a sensitive Monte Carlo simulation workload from an on-premises HPC cluster to Google Cloud. The CISO requires that the data remain encrypted not only on disk and on the network but also while it is being processed in memory, so that even Google administrators or other tenants on the same host cannot inspect it. The engineering team wants to avoid recompiling or refactoring the application code and will accept a small performance impact. Which Google Cloud capability best satisfies these requirements, and why?

  • Encrypt all persistent disks with Customer-Managed Encryption Keys (CMEK) and use VPC Service Controls to prevent exfiltration; this extends encryption to data processed in memory.

  • Run the workload on sole-tenant nodes with Shielded VMs, which isolate tenants at the host level but rely on standard memory protection without encrypting data in use.

  • Enable Confidential VMs, which use processor-based memory encryption (AMD SEV or Intel TDX) to protect data while it is in use, require no application changes, and incur only minor performance overhead.

  • Store encryption keys in Cloud HSM and perform application-level encryption/decryption of all data before and after every CPU operation to ensure in-memory protection.

GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot