A retail analytics startup is bulk-loading 50 TB of historical transaction logs into Google Cloud Storage and then streaming daily updates into a BigQuery dataset. The logs contain no PII and the company is subject only to standard industry security guidelines-there is no requirement for the company to control its own encryption keys. The CTO insists on encryption for data at rest and in transit, wants to avoid any key-rotation or monitoring tasks, and must have the simplest possible configuration ready before next week's launch. Which encryption strategy best satisfies these requirements?
Create Customer-Managed Encryption Keys (CMEK) in Cloud KMS and configure Cloud Storage and BigQuery to use them.
Generate Customer-Supplied Encryption Keys (CSEK) and provide a key with every Cloud Storage upload while allowing BigQuery to use default keys.
Rely on the default Google-managed encryption keys for both Cloud Storage and BigQuery without any additional key configuration.
Integrate an on-premises hardware security module through Cloud External Key Manager so the company retains full key custody.
Google-managed encryption keys are enabled by default for both Cloud Storage objects and BigQuery tables. Google transparently encrypts data before it is written, manages the cryptographic keys (including rotation and availability), and decrypts data when it is read, all without customer configuration or performance impact. Selecting this option therefore provides the required encryption while eliminating operational overhead. Customer-managed (CMEK), customer-supplied (CSEK), or externally managed (EKM) keys would all meet the encryption requirement, but each introduces additional setup, key lifecycle management, and, in some cases, can add latency-contradicting the CTO's mandate for zero extra effort and maximum simplicity.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are Google-managed encryption keys and how do they work?
Open an interactive chat with Bash
How do Customer-Managed Encryption Keys (CMEK) differ from Google-managed encryption keys?
Open an interactive chat with Bash
Why would a company choose Customer-Supplied Encryption Keys (CSEK) or External Key Manager (EKM) over Google-managed encryption keys?
Open an interactive chat with Bash
GCP Professional Data Engineer
Designing data processing systems
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .