GCP Professional Cloud Security Engineer Practice Question

Your security team is reviewing how telemetry data from thousands of warehouse temperature sensors will be ingested into Cloud Storage and queried from BigQuery. The dataset contains no customer or employee identifiers and is subject only to the company's general data-handling policy, which mandates encryption at rest but does not impose any key custody or key-location requirements. The team wants the simplest, lowest-cost approach that still satisfies the policy. Which encryption option should you recommend?

  • Require every sensor gateway to include a customer-supplied encryption key (CSEK) with each upload so Cloud Storage encrypts the data using that key on the server side.

  • Rely on Google-managed default encryption, which automatically encrypts all Cloud Storage objects and BigQuery tables at rest without any extra configuration.

  • Use Cloud External Key Manager (EKM) so the encryption key is generated and stored in a third-party Hardware Security Module outside Google Cloud.

  • Configure Customer-Managed Encryption Keys (CMEK) by creating a symmetric key in Cloud KMS and specifying it for the relevant buckets and datasets.

GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot