GCP Professional Cloud Security Engineer Practice Question

A multinational bank is moving its 8-PB on-premises data warehouse to BigQuery. Its risk office states that the cryptographic keys protecting the data must never reside on any public-cloud infrastructure, and that internal auditors need the ability to revoke key material from the bank's own hardware security modules (HSMs) to make the cloud-resident data immediately unreadable. Which Google Cloud encryption approach for the BigQuery datasets best meets these compliance requirements?

  • Configure BigQuery to use Cloud External Key Manager keys that reside in the bank's on-premises HSMs.

  • Create CMEK keys backed by software in Cloud KMS and assign them to the BigQuery datasets.

  • Use Google-managed default encryption for all tables.

  • Create CMEK keys in Cloud HSM and assign them to the BigQuery datasets.

GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot