🔥 40% Off Crucial Exams Memberships — Deal ends today!

2 hours, 59 minutes remaining!

GCP Professional Data Engineer Practice Question

A healthcare provider stores sensitive patient telemetry in BigQuery. A new regulation requires that the encryption keys protecting this data must remain in an on-premises, FIPS 140-2 Level 3 certified HSM that is managed exclusively by the provider's security team. Analysts must continue to run existing SQL workloads without code changes, and key rotation must occur automatically through the key-management system rather than by updating application logic. Which Google Cloud encryption approach best meets these requirements?

  • Configure BigQuery to use a Customer-Managed Encryption Key that is hosted in an on-premises HSM through Cloud External Key Manager.

  • Protect the dataset with Customer-Supplied Encryption Keys (CSEK) provided in every BigQuery API call.

  • Configure BigQuery with Customer-Managed Encryption Keys stored in Cloud KMS and backed by Cloud HSM.

  • Enable the default Google-managed encryption that automatically secures data at rest.

GCP Professional Data Engineer
Designing data processing systems
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot