GCP Professional Data Engineer Practice Question

A bank is migrating its 50-TB on-premises data warehouse to BigQuery. Regulations stipulate that encryption keys must be fully controlled and rotated by the bank rather than by Google. Data engineers need rights to create and query datasets but must never obtain direct access to the encryption keys themselves. Key rotation should occur automatically to minimize operational effort. Which approach best meets all of these requirements?

  • Deploy an on-premises hardware security module and integrate it with Cloud External Key Manager (EKM); schedule key rotations manually in the external KMS.

  • Before loading, encrypt the data on-premises with your own keys and store it in Cloud Storage; do not configure any BigQuery-side encryption.

  • Create a Cloud KMS key ring in a dedicated security project, protect BigQuery datasets with CMEK, grant the BigQuery service account the CryptoKey Encrypter/Decrypter role on the key, and enable automatic rotation on the key.

  • Use BigQuery's default Google-managed encryption and rely on Google's automatic key rotation.

GCP Professional Data Engineer
Designing data processing systems
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot