1. A global e-commerce company uses Cloud SQL for PostgreSQL to store customer order data. They need to ensure that all data in the database is encrypted at rest and that the encryption keys are stored in a FIPS 140-2 Level 3 validated hardware security module (HSM). Which Cloud SQL encryption option should they choose?
Ensuring data protection
- A. Customer-supplied encryption keys (CSEK)
- B. Database-level encryption with a third-party key manager
- C. Google-managed encryption keys (GMEK)
- D. Customer-managed encryption keys (CMEK) with Cloud KMS
Show answerAnswer
D. Customer-managed encryption keys (CMEK) with Cloud KMS
Cloud SQL supports Customer-managed encryption keys (CMEK) via Cloud Key Management Service (KMS). Cloud KMS offers various key types, including those backed by Cloud HSM, which is FIPS 140-2 Level 3 validated. This allows the company to meet their specific compliance requirement for key storage.