GCP Professional Cloud Security Engineer Practice Question

A financial services company keeps a symmetric Cloud KMS key in a centralized security project (us-central1). Data scientists in a separate ml-dev project must import regulated customer data as a Vertex AI tabular dataset and run a Vertex AI Workbench user-managed notebook VM. Compliance requires both the dataset metadata and the notebook boot disk to use that key for CMEK encryption. What should you do without moving the key or violating least-privilege?

  • Move the key ring from the security project into ml-dev because Vertex AI cannot reference CMEK keys that reside in a different project.

  • Grant the AI Platform service agent for project ml-dev the Cloud KMS CryptoKey Encrypter/Decrypter role on the centralized key and supply that key's full resource ID in the encryption settings when creating both the dataset and the notebook.

  • Simply enable CMEK support on the Vertex AI and AI Notebooks APIs; resources in ml-dev will automatically use any CMEK in the organization that is in the same region.

  • Grant each data scientist the Cloud KMS CryptoKey Encrypter/Decrypter role so they can select the key when creating the dataset and notebook; Vertex AI will then use their user credentials to encrypt the resources.

GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot