A Cloud KMS key protecting CMEK-encrypted Cloud Storage objects was exposed. You must re-encrypt all CMEK-protected objects with a new key, delete the compromised key, and prevent future objects from being written without CMEK. What do you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a new Cloud KMS key, create a new Cloud Storage bucket configured to use the new key as the default CMEK, and copy all objects from the old bucket to the new bucket without specifying a key..
Why this is the answer
The correct approach involves creating a new Cloud KMS key and a new Cloud Storage bucket configured with this new key as its default CMEK. Copying objects from the old bucket to the new one without specifying a key ensures they inherit the new bucket's default CMEK, effectively re-encrypting them. This addresses the re-encryption requirement. Afterward, the old bucket and compromised key can be deleted. The new bucket's default CMEK setting prevents future objects from being written without CMEK. Rotating the key version (option 1) only changes the key used for new encryption operations, not existing objects. Setting a new default key on the existing bucket (option 2) also only affects new uploads; existing objects remain encrypted with the old key. Copying objects to a new bucket while specifying the key in the copy command (option 3) is redundant if the new bucket already has a default CMEK, and the most efficient method is to rely on the default.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed