🔥 40% Off Crucial Exams Memberships — Deal ends today!

2 hours, 27 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your company, a European financial institution, must store transaction logs in Google Cloud Storage and BigQuery. Local regulations mandate that the cryptographic keys used to encrypt the data never leave the bank's on-premises HSM, and auditors require demonstrable separation between data at rest and the encryption keys. Which Google Cloud capability best satisfies these requirements while avoiding custom application-level encryption?

  • Implement client-side envelope encryption in your application and upload pre-encrypted objects.

  • Configure Cloud Storage and BigQuery with customer-managed encryption keys (CMEK) stored in Cloud KMS.

  • Rely on Google default encryption for both services because keys are always encrypted by Google.

  • Use Cloud External Key Manager (EKM) to protect the datasets with keys resident in the on-premises HSM.

GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot