🔥 40% Off Crucial Exams Memberships — Deal ends today!

3 hours, 1 minute remaining!

GCP Professional Cloud Security Engineer Practice Question

Your organization is migrating sensitive genomics data to Cloud Storage. A regional privacy law requires that the encryption keys must never leave the company-owned, on-premises HSM cluster, and security policy mandates that any dataset can be rendered unreadable at once by disabling the on-prem key. Developers do not want to modify application code beyond selecting an encryption option for the bucket. Which Google Cloud approach best satisfies these requirements?

  • Configure CMEK with a software-backed symmetric key stored in Cloud KMS and rotate it quarterly.

  • Enable Customer-Managed Encryption Keys backed by Cloud HSM for the bucket.

  • Protect the bucket with a Cloud External Key Manager (EKM) key and enable CMEK using the external key reference.

  • Rely on Google default encryption and enforce Bucket Lock to prevent key access by Google personnel.

GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot