GCP Professional Cloud Security Engineer Practice Question
A financial services company keeps a symmetric Cloud KMS key in a centralized security project (us-central1). Data scientists in a separate ml-dev project must import regulated customer data as a Vertex AI tabular dataset and run a Vertex AI Workbench user-managed notebook VM. Compliance requires both the dataset metadata and the notebook boot disk to use that key for CMEK encryption. What should you do without moving the key or violating least-privilege?
Grant each data scientist the Cloud KMS CryptoKey Encrypter/Decrypter role so they can select the key when creating the dataset and notebook; Vertex AI will then use their user credentials to encrypt the resources.
Grant the AI Platform service agent for project ml-dev the Cloud KMS CryptoKey Encrypter/Decrypter role on the centralized key and supply that key's full resource ID in the encryption settings when creating both the dataset and the notebook.
Move the key ring from the security project into ml-dev because Vertex AI cannot reference CMEK keys that reside in a different project.
Simply enable CMEK support on the Vertex AI and AI Notebooks APIs; resources in ml-dev will automatically use any CMEK in the organization that is in the same region.
Vertex AI uses a per-project Google-managed service agent (service-@gcp-sa-aiplatform.iam.gserviceaccount.com) to create and manage datasets and Workbench notebook VMs. Grant that service agent the Cloud KMS CryptoKey Encrypter/Decrypter role (roles/cloudkms.cryptoKeyEncrypterDecrypter) on the centralized key and supply the key's full resource name (projects/security/locations/us-central1/keyRings/…/cryptoKeys/…) in the encryptionSpec.kmsKeyName field when creating each dataset and notebook. Cross-project CMEK is supported when the key and resources share the same region. Moving the key, enabling an automatic switch, or giving individual users key access is unnecessary and would violate least privilege.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Cloud KMS and what role does it play in CMEK encryption?
Open an interactive chat with Bash
What is the AI Platform service agent and why is it required for Vertex AI CMEK encryption?
Open an interactive chat with Bash
How does cross-project CMEK support work in Google Cloud, and why is it important?
Open an interactive chat with Bash
What is CMEK in GCP?
Open an interactive chat with Bash
What does the AI Platform service agent do in GCP?
Open an interactive chat with Bash
How does cross-project CMEK work in GCP?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .