🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 51 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your organization stores raw data in a Cloud Storage bucket in europe-west3 and ingests it into a BigQuery dataset in the EU multi-region. Audit logs will be archived daily and signed with an asymmetric key. Policy requires that CMEK keys reside in the same Google Cloud location as the data whenever possible, with the fewest key rings. Which design meets these constraints?

  • Create two key rings: one in eu with a symmetric key for BigQuery, and one in europe-west3 with a symmetric key for Cloud Storage. Add an asymmetric RSA-2048 signing key in either ring.

  • Create three key rings: europe-west3, eu, and global. Place a symmetric key for each workload in its own ring and the signing key in the global ring.

  • Create one key ring in the eu multi-region containing two symmetric encryption keys for Cloud Storage and BigQuery, plus an asymmetric RSA signing key.

  • Create one key ring in europe-west3 containing a single symmetric encryption key shared by Cloud Storage and BigQuery, plus an asymmetric signing key.

GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot