GCP Professional Cloud Security Engineer Practice Question

A retail bank headquartered in Frankfurt is migrating customer account statements to Google Cloud. German banking regulations require that every copy of the statements, as well as the encryption keys protecting them, remain physically in Germany. Operations wants to avoid manual key-handling tasks but still control when keys are rotated every quarter. Which Google Cloud design best fulfills the regulatory and operational requirements?

  • Create a custom dual-region bucket spanning europe-west3 (Frankfurt) and europe-central2 (Warsaw) and encrypt it with a Cloud KMS CMEK stored in europe-west3.

  • Configure a Cloud Storage custom dual-region bucket across europe-west3 and europe-west1 (Belgium) and protect data with customer-supplied encryption keys that are uploaded during each quarterly rotation.

  • Use a Cloud Storage multi-region bucket in europe-4 and rely on Google-managed encryption keys to avoid key-rotation tasks.

  • Store the statements in a Cloud Storage regional bucket in europe-west3 protected by a Cloud KMS CMEK whose key ring is also in europe-west3, and configure automatic key rotation for 90-day intervals.

GCP Professional Cloud Security Engineer
Supporting compliance requirements
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot