GCP Professional Cloud Security Engineer Practice Question

Your security team must ensure that encryption keys used for a new Cloud Storage bucket remain exclusively in the company's on-premises HSM cluster. You have deployed the vendor's Cloud External Key Manager (EKM) connector and obtained the key's URI (ekm://…). However, when you try to create the first symmetric CryptoKeyVersion in Cloud KMS with protection level EXTERNAL and the external_key_uri field set to that URI, the request fails with the error message:

"PERMISSION_DENIED: external key URI is not allowed by any EkmConnection".

Which prerequisite action in Google Cloud did you most likely omit, causing this error?

  • Grant the Cloud KMS service account the CryptoKey Encrypter/Decrypter role on the on-premises HSM that holds the key.

  • Create an EkmConnection resource in the same Cloud KMS location that explicitly lists the external key's URI.

  • Enable Private Service Connect for the project and add the external key URI to a VPC Service Controls perimeter.

  • Import the external key material into Cloud KMS by creating an import job and using the key's wrapped representation.

GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot