Using Google Groups you created and following Google best practices and simplicity, how should you control access and encryption for Cloud Storage?
Choose an answer
Tap an option to check your answer.
Correct answer: Grant predefined IAM roles to the Google Groups and rely on Google-managed encryption at rest.
Why this is the answer
The correct answer emphasizes simplicity and best practices. Granting predefined IAM roles to Google Groups is simpler and generally more secure than creating custom roles, as predefined roles are maintained by Google and cover common use cases. Relying on Google-managed encryption at rest is the default and recommended practice for Cloud Storage, as it provides strong encryption without requiring any user configuration or key management, aligning with simplicity and best practices. Incorrect options: Using CSEK adds complexity for key management, which goes against simplicity unless there's a specific compliance requirement. Enabling default storage encryption is part of Google-managed encryption, but combining it with custom IAM roles adds unnecessary complexity compared to predefined roles. Setting a default Cloud KMS key for buckets is an option for customer-managed encryption keys (CMEK), which adds key management overhead compared to Google-managed encryption, again deviating from simplicity unless specifically required.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed