🔥 40% Off Crucial Exams Memberships — Deal ends today!

3 hours, 1 minute remaining!

GCP Professional Cloud Security Engineer Practice Question

Your security team keeps a 256-bit AES key in an on-premises FIPS-validated HSM and wants to reuse that key as the customer-managed encryption key (CMEK) for a BigQuery dataset stored in the europe-west1 region. You must import the key into Cloud KMS while ensuring the key material is never sent to Google in plaintext. Which procedure satisfies Google Cloud's requirements and the security goal?

  • Create a hardware-backed key in Cloud HSM and copy the on-premises key bytes into the first key version through the KMS REST API without wrapping.

  • Configure Cloud External Key Manager (EKM) to reference the on-premises HSM URI and assign that external key to the BigQuery dataset instead of importing the key into Cloud KMS.

  • Create a key ring and symmetric key in europe-west1, generate a SOFTWARE protection-level import job, wrap the AES key offline with AES-KWP (RFC 5649) using the job's public key, then run gcloud kms keys versions import to upload the wrapped key.

  • Create a key ring in the global location and paste the Base64-encoded 32-byte key directly into the first key version by using the Cloud Console's Upload key material option.

GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot