A BigQuery table ingests messages from a Pub/Sub subscription using Google-managed encryption. Org policy requires using CMEK from a centralized Cloud KMS project for data at rest. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a new BigQuery table by using customer-managed encryption keys (CMEK), and migrate the data from the old BigQuery table..
Why this is the answer
The correct answer is to create a new BigQuery table with CMEK and migrate the data because BigQuery tables, once created, cannot have their encryption key type changed from Google-managed to CMEK. The existing data in the table is encrypted with Google-managed keys. To comply with the organization's policy requiring CMEK for data at rest, a new table must be created with the specified CMEK from the centralized Cloud KMS project. Dataflow is not directly used to change BigQuery table encryption. Creating a new Pub/Sub topic with CMEK is irrelevant to the BigQuery table's encryption, as the policy specifically targets data at rest in BigQuery. There's no need to create a new Pub/Sub topic if the existing one is already feeding the data correctly, as the policy focuses on BigQuery's data at rest encryption.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed