🔥 40% Off Crucial Exams Memberships — Deal ends today!

3 hours, 1 minute remaining!

GCP Professional Data Engineer Practice Question

A healthcare provider is building a Dataflow pipeline that loads sensitive genomic records into a BigQuery dataset located in the europe-west2 region. Regulations require that: 1) all data be encrypted with keys that remain exclusively in the hospital's on-premises HSM, 2) every decryption operation be auditable in Cloud Logging, and 3) no application code changes be needed beyond configuration. Which key-management approach should you recommend?

  • Use Cloud External Key Manager (EKM) with an externally managed key and enable CMEK on the BigQuery dataset and Dataflow temporary buckets.

  • Create Customer-Managed Encryption Keys (CMEK) in Cloud KMS and rotate them weekly.

  • Enable default Google-managed encryption for BigQuery and Dataflow artifacts and rely on Cloud Audit Logs.

  • Configure Customer-Supplied Encryption Keys (CSEK) and pass the key with every Dataflow and BigQuery request.

GCP Professional Data Engineer
Designing data processing systems
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot