GCP Professional Cloud Security Engineer Practice Question

A healthcare provider is migrating a 10-year document archive from an on-premises NAS to Cloud Storage. Internal policy requires the following:

  • If regulators mandate immediate disposal, the data must become unreadable within 24 hours.
  • Encryption keys must reside in Google Cloud to avoid having to operate or audit on-premises HSMs.
  • Google must be unable to decrypt the data using its own keys. Which encryption strategy best satisfies these requirements?
  • Adopt Cloud External Key Manager so the bucket is protected with a key stored in an on-premises HSM, then revoke access to that key if disposal is mandated.

  • Rely on Google-managed default encryption and configure an object lifecycle delete rule to remove data upon regulatory request.

  • Perform client-side encryption using customer-supplied encryption keys (CSEK), store the keys off-platform, and discard them when disposal is needed.

  • Enable a symmetric customer-managed encryption key in Cloud KMS for the bucket and invoke key-version destruction when disposal is required.

GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot