To enforce customer-managed encryption keys with separation of duties and Google best practices using Cloud KMS, which two actions should you take?
Choose an answer
Tap an option to check your answer.
Correct answer: Provision Cloud KMS in its own project., Do not assign an owner to the Cloud KMS project..
Why this is the answer
Provisioning Cloud KMS in its own project is a Google best practice for security and separation of duties. This isolates key management from the resources being encrypted, reducing the blast radius in case of a compromise. Not assigning an "owner" to the Cloud KMS project reinforces this by preventing a single individual from having ultimate control over both the keys and the encrypted data. Instead, granular roles should be used. Provisioning KMS in the same project where keys are used defeats the purpose of separation of duties. Granting roles/cloudkms.admin to the owner of the project that uses the keys also violates separation of duties, as that owner would have too much control. Assigning the Cloud KMS project owner role to a different user is a step in the right direction but still grants an overly broad "owner" role, which is generally discouraged for service projects.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed