🔥 40% Off Crucial Exams Memberships — Deal ends today!

45 minutes, 39 seconds remaining!

GCP Professional Cloud Security Engineer Practice Question

A financial-services company protects multiple Cloud Storage buckets with a single symmetric CMEK key stored in Cloud KMS. Internal policy mandates that the key must rotate every 90 days without requiring engineers to run scripts, and auditors need to trace exactly which key version encrypted each object. What is the most operationally efficient way to satisfy both requirements while avoiding downtime for the buckets?

  • Delete the current primary key version every 90 days so that Cloud Storage automatically falls back to Google-managed encryption, then recreate and reassign the CMEK key after audits are complete.

  • Schedule a Cloud Function to export the existing key material and immediately re-import it as a new key version every 90 days, updating IAM policies to grant access to the re-imported key.

  • Configure automatic rotation on the symmetric key by setting a 90-day rotation period and a next-rotation timestamp; Cloud KMS will create a new primary key version on schedule, and Cloud Storage will transparently start using it while recording the version in object metadata and audit logs.

  • Every 90 days, create a new key ring that contains a freshly generated key and use a deployment script to update each bucket's CMEK reference to the new key, then disable the old key ring.

GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot