🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 1 minute remaining!

GCP Professional Cloud Security Engineer Practice Question

Your security team mandates that every newly created secret be encrypted with a customer-managed key that is protected by Cloud HSM. Secrets will use the automatic (global) replication policy because workloads run world-wide. As a Cloud Security Engineer, what must you do to meet the requirement and keep the secrets usable by applications?

  • Rely on the default Google-managed encryption and enable Secret Manager "HSM protection" at the organization level; no Cloud KMS roles are necessary.

  • Configure Secret Manager to use a Cloud EKM key URI; the external key's geographic location is ignored when the replication policy is global.

  • Create an HSM-backed key in any single region, then reference it when you update existing secrets from Google-managed encryption to CMEK.

  • Create an HSM-backed symmetric key in the global Cloud KMS location and grant the Secret Manager service agent the Cloud KMS CryptoKey Encrypter/Decrypter role on that key before creating each secret.

GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot