Sensitive data in Cloud Storage must support key rotation and will be processed in Dataproc. Which encryption approach follows Google security best practices?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a key with Cloud Key Management Service (KMS). Set the encryption key on the bucket to the Cloud KMS key..
Why this is the answer
Using Cloud KMS to set the encryption key on the bucket is the recommended Google best practice. This method, known as Customer-Managed Encryption Keys (CMEK), integrates directly with Cloud Storage and Dataproc. It allows for automatic key rotation managed by KMS, which is a key requirement. Dataproc can seamlessly access data encrypted with CMEK. Encrypting data using the KMS encrypt method directly would require manual decryption before Dataproc could process it, adding complexity. GPG keys are not a native Google Cloud encryption solution and would require custom integration, making key management and rotation more difficult. Customer-supplied encryption keys (CSEK) require you to manage and supply the key for every operation, which is less convenient and secure than CMEK for ongoing processing, and doesn't inherently support automated key rotation.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed