You must store sensitive data in BigQuery while using encryption keys generated outside Google Cloud. What sequence implements this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Import a key in Cloud KMS. Create a dataset in BigQuery using the customer-supplied key option and select the created key..
Why this is the answer
The correct option allows you to use encryption keys generated outside Google Cloud by importing them into Cloud KMS. BigQuery then supports using these customer-supplied encryption keys (CSEK) directly when creating a dataset, ensuring the data at rest is encrypted with your external key. The first two incorrect options fail because they generate a new key in Cloud KMS, which doesn't meet the requirement of using a key generated outside Google Cloud. The third incorrect option imports the key correctly but then stores data in Cloud Storage and uses a Dataflow pipeline, which is an unnecessary and complex step for BigQuery data encryption; BigQuery can directly use CSEK.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed