A fintech startup is building a proof-of-concept analytics pipeline on Google Cloud. They will ingest a limited set of non-production customer transaction data into Cloud Storage and BigQuery for two weeks. The security team insists that the data must be encrypted at rest; however, they do not want to create, rotate, or otherwise manage any encryption keys during this short engagement. Which encryption approach should the data engineering team choose to satisfy the requirement with the least operational overhead?
Integrate a third-party Hardware Security Module via Cloud External Key Manager (EKM) and use externally hosted keys.
Rely on the default Google-managed encryption keys that automatically protect data at rest in Cloud Storage and BigQuery.
Create a Cloud KMS key ring and configure Customer-Managed Encryption Keys (CMEK) for all Cloud Storage buckets and BigQuery datasets.
Generate Customer-Supplied Encryption Keys (CSEK) locally and provide them with every upload to Cloud Storage.
By default, Google Cloud automatically encrypts all data at rest using Google-managed encryption keys that are created, stored, and rotated by Google. Selecting the default Google-managed encryption keys meets the security team's requirement for encryption without requiring the project team to provision Cloud KMS key rings, configure Customer-Managed Encryption Keys (CMEK), maintain Customer-Supplied Encryption Keys (CSEK), or integrate an external key management system (EKM). The other options introduce additional setup, rotation, or lifecycle-management tasks that contradict the goal of avoiding key management effort.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
How does Google-managed encryption work?
Open an interactive chat with Bash
What is the difference between CMEK and Google-managed encryption keys?
Open an interactive chat with Bash
Why is Customer-Supplied Encryption (CSEK) not recommended here?
Open an interactive chat with Bash
GCP Professional Data Engineer
Designing data processing systems
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .